{"slug": "metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug", "title": "Meta’s Muse AI Agent Has Been Downloaded Half a Million Times — With a Serious Bug", "summary": "Meta patched a zero-day vulnerability in its Muse AI agent after cybersecurity researcher Patrick Wardle demonstrated that an attacker could redirect users' Muse dictations and access tokens to a malicious server, with Meta Superintelligence Labs head David Singleton confirming the fix on Tuesday while disputing Wardle's claim that the flaw could be exploited remotely without pre-existing malware. The macOS Muse app was downloaded more than half a million times in its first week, according to internal data seen by The Information, and users are advised to update the app immediately to receive the security fix.", "body_md": "If you’ve seen a cartoonish character at the top of your Instagram feed lately, that’s Muse. Meta’s newest AI agent, or bot, [wants to be your digital assistant](https://www.cnet.com/tech/services-and-software/meta-muse-ai-agent-personal-computer-2026-news/). But Meta had to rush to patch a serious zero-day bug in Muse’s code this week, highlighting just how treacherous it can be to hand over the keys to your digital life to agentic AI.\n\nPatrick Wardle, founder of the cybersecurity firm Objective-See, was the first to spot the zero-day bug. He outlined the vulnerability [in X posts](https://x.com/patrickwardle/status/2102045926474785265), showing how a bad actor could trick the AI agent into sending a person’s Muse dictations, or audio captures, and access tokens to their own malicious server, not Meta’s servers. Wardle [has a long history](https://www.forbes.com/sites/thomasbrewster/2015/12/17/facebook-instagram-security-research-threats/) of finding bugs in Meta’s software.\n\nThe head of Meta’s Superintelligence Labs, David Singleton, replied to Wardle’s X post on Tuesday to [confirm the company has patched](https://x.com/dps/status/2102248329111634067?s=20) the vulnerability. He added that the bug required malware to already be on a user’s computer for the exploit to work; Wardle disagrees, saying it is possible for a hacker to exploit this flaw remotely.\n\nTo prevent your Muse AI agent from being hacked, **update your MacOS Muse app right now**. This will ensure you’re running the latest version of the program, including the new security fix. No additional action is needed from you.\n\n## A one-off bug or persistent pattern?\n\nSingleton wrote of the incident: “We strive to be extremely transparent about privacy and security in Muse as we know this is important to maintain your trust.” We absolutely need tech companies to be transparent, but there is still a lot unknown about AI agents like Muse.\n\nAt first glance, Muse has had a successful entrance into an already crowded field of AI agents, including those from OpenAI, SpaceXAI and Anthropic. The MacOS app was downloaded more than half a million times during its first week, according to internal data seen [by The Information](https://www.theinformation.com/briefings/exclusive-metas-muse-surpassed-500-000-users-first-week), making it one of the more popular AI agent choices. But to get the most value out of your AI agent, you need to grant it permission to access a lot of different things. To have Muse make you a dinner reservation, for example, it needs to be able to use your computer, access the web and potentially use your credit card info to hold the table. \n\nPrivacy and security concerns are two of the most serious concerns with generative AI. No tech company has fully addressed all the various harms that will come from AI, be it [cybersecurity hacks](https://www.cnet.com/tech/services-and-software/ai-agents-are-a-cybersecurity-nightmare-thats-only-just-begun/) or losing control over our personal information used by the AI. But Meta has a longer track record than most AI startups, and its history isn’t the most reassuring. Just consider the [2016 Cambridge Analytica scandal](https://www.cnet.com/news/politics/facebook-cambridge-analytica-data-mining-and-trump-what-you-need-to-know/) that revealed millions of Facebook users’ data had been used improperly, or its more recent court battle and settlement [over failing to protect children online](https://www.cnet.com/tech/services-and-software/meta-google-negligent-social-media-addiction-trial-california/).\n\nThese security reports come ahead of Wednesday’s Meta Connect, where CEO Mark Zuckerberg is expected to show us more about how the company is thinking about AI and [AI hardware](https://www.cnet.com/tech/services-and-software/openai-apple-lawsuit-hardware-plans-commentary/). Meta Connect has traditionally focused on Meta’s smart glasses, but [rising public backlash](https://www.cnet.com/tech/mobile/lordes-war-cry-signals-smart-glasses-backlash-among-women/) has cast a lot of doubt on the long-term viability of the devices, sometimes [dubbed “pervert glasses”](https://www.cnet.com/tech/mobile/meta-smart-glasses-without-cameras-announcement-imminent-reportedly/) due to their recording capabilities.\n\nIf Meta is going to continue down the agentic AI path, tech users need to be able to trust the company to build it responsibly. But the public’s faith in AI companies [has dwindled in recent days](https://www.cnet.com/tech/services-and-software/ai-doomsday-human-extinction-regulation-tech-giants-powerful-not-safer/), thanks to AI researchers airing concerns that the technology could lead to the extinction of humanity.", "url": "https://wpnews.pro/news/metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug", "canonical_source": "https://www.cnet.com/tech/services-and-software/metas-muse-ai-agent-zero-day-cybersecurity-bug-patched/", "published_at": "2026-09-23 17:52:30+00:00", "updated_at": "2026-09-23 18:29:58.658385+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-products", "artificial-intelligence"], "entities": ["Meta", "Muse", "Patrick Wardle", "Objective-See", "David Singleton", "Meta Superintelligence Labs", "The Information", "Mark Zuckerberg"], "alternates": {"html": "https://wpnews.pro/news/metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug", "markdown": "https://wpnews.pro/news/metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug.md", "text": "https://wpnews.pro/news/metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug.txt", "jsonld": "https://wpnews.pro/news/metas-muse-ai-agent-has-been-downloaded-half-a-million-times-with-a-serious-bug.jsonld"}}