Reasonary AI
Wed, September 23, 2026 at 1:00 PM

about 1 hour ago
Meta has issued a hotfix for its Muse AI assistant after a researcher disclosed a serious zero-day flaw in the app. Mac security researcher Patrick Wardle found the flaw on September 21 and released proof-of-concept attacks that hijacked the entire agent.
The flaw lived in an undocumented Muse setting that controls the remote server used to transcribe the assistant's spoken dictation. Any program running as the logged-in user could redirect that dictation traffic to an attacker-controlled endpoint without needing extra macOS permissions.
Attackers could then silently capture the user's dictated audio, read the account's chat history, and control the assistant from any device. Wardle showed that the stolen token let him direct the Muse app on his own iPhone to report its exact location.
He also demonstrated that a hijacked agent could write malicious files to disk and take pictures without alerting the user. Meta said it removed the vulnerable setting within hours of the disclosure, calling the risk to users quite low in practice.
Security experts note that infostealer malware routinely reaches Macs today, so attackers who need local code execution can often obtain that access in practice without much difficulty.
Wardle said a remote attacker could still hijack Muse through a ClickFix trick that fools users into running one command. Because the Muse account works across devices, the stolen token allowed commands to be sent to the assistant on other machines.
Wardle advised users not to install Muse, calling the flaw trivial to turn the assistant into the ultimate Mac backdoor. He chose full disclosure rather than reporting the flaw privately to Meta, saying that approach often gets bugs fixed fastest.
The Open Worldwide Application Security Project warns that AI agents introduce risks including prompt injection, tool abuse and data exfiltration. Security guidance holds that an agent should not hold more access than it needs or turn untrusted instructions into sensitive actions.
Wardle's warning came as Amazon confirmed it had blocked Muse from shopping on its platform, saying that Meta never obtained permission and never notified Amazon in advance.
David Singleton of Meta Superintelligence Labs said the company issued the hotfix shortly after midnight Tuesday to address the flaw. He called the incident a local privilege escalation rather than a remote exploit, adding that the risk to users was low.
Meta promoted Muse as built from the ground up for privacy and security when it launched the agent on September 8. The agent books travel, sends emails, shops online and tracks goals, requiring broad access to user accounts and device features.
The vulnerability required an undocumented setting to be removed, and Meta said it eliminated that setting rather than moving dictation processing entirely onto the Mac device itself.
Muse downloads reportedly outpaced ChatGPT's 12-day debut in the United States and Canada, and Meta stock climbed 11 percent Monday. Still, Amazon's block and the disclosure raised fresh scrutiny as Meta tries to close ground on rival AI providers including OpenAI.