Meta has released an immediate patch for its Muse on macOS app after discovering a serious zero-day vulnerability that could allow malware to manipulate the app's AI agent . The issue was discovered by cybersecurity researcher Patrick Wardle and is linked to the way Muse handles certain internal settings and features that are not available to the average user.

A hidden setting paved the way for an attack
According to Wardle's findings, the vulnerability was related to an undocumented setting in Muse that could be controlled by other applications running on the same Mac. Through this feature, an attacker who had already managed to execute code on the device could change the destination of transcription processing.
Instead of the data being directed to Meta's infrastructure, it could be redirected to a server controlled by the attacker. The result was an attack chain that could lead to the abuse of the AI agent's own privileges.
See also: Meta Muse: Amazon blocks AI shopping agent
The AI agent could act as an attacker's "tool"
The most concerning aspect wasn't just the transcription data leak. In his tests, Wardle was able to leverage Muse's capabilities to have the AI agent perform actions on his behalf.
The proof-of-concept exploits he created showed that he could, among other things, ask Muse to take photos and create malicious files on disk. In several of the tests, these actions could be performed without any clear warning to the user.
This highlights a different type of risk that accompanies the new generation of AI applications. Traditional malware needs to include mechanisms to access files or other operating system functions. An AI agent, by contrast, may already have such capabilities , and therefore a vulnerability in the way it is controlled can turn the assistant itself into an action execution mechanism.
Muse's architecture created additional risk
Some design choices in the app also seem to have played a role. Muse dictation is done via a cloud infrastructure rather than being done exclusively locally on the device. At the same time, the ability to access undocumented settings from any app created an additional entry point.
This incident shows why the security of AI agents is not limited to protecting the AI model alone. Equally critical is the way the model connects to the operating system, files, input devices, and online services.
Meta's response and the importance of local access
Meta released a hotfix a few hours after the findings were made public. The company downplayed the actual risk to most users, noting that the attack could not be carried out remotely over the internet.
Exploiting the vulnerability already required executing malicious code on the victim's computer, under the user's account. This means that Muse was not an initial remote penetration mechanism in itself.
See also: Meta invests in AI agent Muse to make up for lost ground in the artificial intelligence race
However, this distinction does not eliminate the importance of the problem. In a real attack, an attacker who has already gained limited access to a Mac could look for ways to exploit the privileges available to other applications. An AI agent with access to more features can be a particularly interesting intermediate target.

Muse is already under increased scrutiny
The revelation comes at a critical time for Meta, as Muse is part of the company's effort to strengthen its presence in the competitive space of AI agents.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Meanwhile, the app has already faced other challenges. Amazon reportedly blocked Muse from its e-commerce platform, claiming that Meta had not received the required permission for such access.
Despite the security incident, initial interest in Muse appears to have been particularly high. According to estimates for the first 12 days of launch, downloads of the mobile app in the US and Canada exceeded the corresponding performance of ChatGPT in its own first 12 days. During the same period, Meta's stock rose about 11% in one session.
See also: Meta Muse: The AI assistant doesn't know how it works exactly
AI agents need a different approach to security
The Muse incident highlights a broader issue that will increasingly concern the market. As AI assistants gain the ability to perform real actions rather than simply answer questions, the consequences of a vulnerability can become much greater.

For users, installing the latest updates is the first and most important step. For developers, however, the lesson is deeper: the internal settings, the permissions of agents, and their communication with the operating system must be designed with the same priority as the capabilities of artificial intelligence.
Muse thus shows that the next generation of cyberattacks may not only target the AI model, but the very agent that has the ability to act on behalf of the user.
