Meta issues patch for Muse AI app following zero-day exploit discovery

Published:

Meta has released a patch for its Muse macOS application following the identification of a zero-day vulnerability that could potentially allow unauthorized users to take control of the AI agent. This flaw was discovered by security researcher Patrick Wardle, who noted that it exploited an undocumented setting within Muse, enabling attackers to redirect transcription processing from Meta’s servers to their own systems, as reported by The Verge.

The vulnerability stemmed from several design choices, including the decision to process Muse dictation in the cloud rather than on the device itself. Additionally, the app allowed any application to manipulate all of Muse’s undocumented settings. Wardle demonstrated proof-of-concept attacks that enabled him to take pictures and write malicious files to disk without alerting the user in many instances.

Wardle expressed concerns about the security measures in place, suggesting that the design of Muse could allow attackers to leverage the AI assistant’s privileges for malicious purposes. He indicated that instead of developing complex malware, attackers could simply exploit the AI assistant itself. This criticism contrasts sharply with Meta’s earlier emphasis on Muse’s privacy and security features during its announcement.

In response to the vulnerability, Meta acted swiftly, issuing a patch shortly after the report was published. The company maintains that the real-world security risks were minimal, as the exploit required local access to the user’s device. David Singleton from Meta Superintelligence Labs clarified that this was a local privilege escalation attack, meaning that it necessitated malicious code already running on the user’s machine, thus limiting the practical risk to users of the Muse Mac app.

Despite the rapid resolution of the issue, the exploit has emerged at a challenging time for Meta, as the company seeks to regain its competitive edge in the AI sector. Recently, Amazon blocked Muse from accessing its e-commerce platform, claiming that Meta had not secured permission to do so. Nevertheless, the launch of Muse has seen significant success, with estimated downloads of the mobile app reportedly surpassing those of ChatGPT during its initial 12 days in the US and Canada. Following the launch, Meta’s stock experienced an 11 percent increase.

Follow our Tech news coverage for related developments.

Share post:

Subscribe

Popular

More like this
Related

AI’s effectiveness hinges on data quality, emphasizes SAS’s Reece Clifford in Dubai discussion

In a recent discussion in Dubai, Reece Clifford, Public Sector Pre-Sales Manager for the Middle East, Turkey, and Africa at SAS, highlighted the critical role of data quality in the effectiveness of artificial intelligence (AI). He emphasized that as AI…

AI workers express skepticism over fears of technology posing existential threats

Recent discussions among employees from leading artificial intelligence (AI) firms reveal a notable skepticism regarding fears that unchecked AI development could pose existential threats to humanity. According to a report by the BBC, individuals from companies such as OpenAI, Meta,…

UAE Cyber Security Council launches V7 AI malware detection model with 94.7% accuracy

The UAE Cyber Security Council has unveiled a new artificial intelligence model, V7, designed to detect malware with an impressive accuracy rate of 94.7%. This model was introduced during the GISEC Global 2026 event in Dubai, where the council highlighted…

Nozomi Networks to showcase cyber resilience solutions at GISEC Global 2026 in Dubai

Nozomi Networks, a leader in operational technology (OT), Internet of Things (IoT), and cyber-physical systems (CPS) cybersecurity, is set to showcase its cyber resilience solutions at GISEC Global 2026. The event will take place at the Dubai Exhibition Center (DEC)…