Meta Rushes Muse Hotfix After Zero-Day Let Local Malware Hijack Its Mac AI Agent

Meta patched a SEV-2 zero-day in the Mac version of its Muse AI assistant on 24 September after researcher Patrick Wardle showed that any locally running malicious code could redirect Muse's dictation traffic to an attacker-controlled server and capture audio plus auth tokens.

Meta Rushes Muse Hotfix After Zero-Day Let Local Malware Hijack Its Mac AI Agent

Meta pushed an emergency Muse for Mac hotfix on 24 September 2026 to close a SEV-2 zero-day that would let any locally running malicious code redirect the AI assistant's dictation traffic to an attacker-controlled server, siphoning off both raw audio and the authentication tokens attached to it — a two-week hole in software Meta had only launched publicly on 8 September.

How the exploit worked

Security researcher Patrick Wardle disclosed the flaw to Meta on Monday 23 September. Muse for Mac stores an internal developer setting for the transcription-server endpoint inside local app preferences with no signature check, so any process already running as the user — malware, an over-privileged Homebrew formula, a malicious VS Code extension — could rewrite that endpoint and turn every dictation session into an out-of-band data leak, without Muse ever prompting the user.

Meta corporate signage outside its Menlo Park headquarters

Local-priv, not remote — but landed right before Connect

Meta and Wardle both stressed this was a local privilege-escalation flow, not a remote exploit, and Wardle himself judged the practical risk to Muse users "quite low." Even so, the timing landed brutally: the hotfix went out a day before Meta Connect, at which Zuckerberg unveiled a $1,300 VR headset and six new AI-glasses SKUs, and the same week that Transluce documented OpenAI agents breaching Australia's Medicare portal.

The bigger picture

Muse is the second consumer AI-agent product this month to ship a preferences file that a local attacker can weaponize, following the NYC Council's 25 September AI oversight package that would require third-party validation before any such product could be sold to city residents. Frontier-agent security is starting to look less like a policy debate and more like a shipping bug queue.

Reporting based on coverage from Gizmodo, Forkast and Eastern Herald.

Category: Cyber Security

Tags: AI Cybersecurity AI Agents Zero-Day AI Security

Related Articles