Meta patches a Muse flaw that let local code redirect transcription

reported by 3 outlets· 3 articles · confidence: medium · first seen 2026-09-21 22:24 UTC

What this means for you

If you run Muse on a Mac, update it: Meta says a fix has shipped, and the flaw let code already on the machine redirect transcription away from Meta's servers. For anyone building privileged local agents, the shape of the bug is the point — an undocumented setting, not a model failure. Meta has published no advisory.

Meta has patched a zero-day in Muse, its macOS AI assistant, after security researcher Patrick Wardle found that an undocumented setting let code running on the machine redirect transcription processing away from Meta's servers. Wired reports Meta says the flaw would have let an attacker do "whatever" they wanted on a victim's Mac. Meta has not said how many users were exposed, or how long the setting shipped. Ars Technica describes a ClickFix attack as one route to taking over the agent, and not the only one, so whether the patch closes every route is unclear.

Key facts

  • ·Security researcher Patrick Wardle found the vulnerability in Meta's Muse macOS app source
  • ·The flaw used an undocumented Muse setting that let local code redirect transcription processing away from Meta's servers source
  • ·Meta says it has issued a fix for the Muse zero-day source
  • ·Meta says the flaw would have let attackers do "whatever" they wanted on a victim's Mac source
  • ·Ars Technica reports a ClickFix attack was one way to hijack the agent, and not the only one source

What the sources say

  • Ars Technica AI — Reports that a straightforward attack technique was enough to seize control of the assistant
  • The Verge AI — Identifies the researcher, explains the setting that was abused, and reports Meta has patched it
  • Wired AI — Carries Meta's account of the damage the flaw allowed, and asks what it says about assistant apps

Sources

The original reporting. Follow these — they did the work.

Related stories

← the wire