What happened
Meta has released a patch for its Muse macOS app after a zero-day vulnerability was discovered that could let an attacker take control of the AI agent.
The bug was found by security researcher Patrick Wardle and involved an undocumented Muse setting.
According to the finding, that setting could let attackers running local code redirect transcription processing away from Meta's servers.
Why it matters
The flaw shows how an AI agent's backend routing can become an attack surface: if transcription work can be redirected, data intended for a vendor's servers may not stay there.
Because the issue was a zero-day and required local code execution, it highlights the risk posed by undocumented settings that may not receive the same scrutiny as documented features.
Key facts
Meta issued a patch for its Muse macOS app.
The vulnerability was a zero-day that could allow someone to take control of the AI agent.
Security researcher Patrick Wardle found the bug.
The bug used an undocumented Muse setting.
The setting enabled potential attackers running local code to redirect transcription processing from Meta's servers.
What to watch next
Whether Meta discloses further technical details about the undocumented setting and how the redirect was possible.
Whether the patch is confirmed to fully close the issue, and whether similar undocumented settings exist elsewhere in the app.
