Skip to content
Türkçe

Meta · Safety and security · Agents

Meta closed a Muse vulnerability that could open the way to users’ email and files

Published: 4 sourcesTürkçe

The flaw, found by Mac security researcher Patrick Wardle, used an undocumented setting to redirect dictation traffic in the Muse Mac app to another server and capture authentication tokens. Because Muse asks for access to files, email, calendar, messages and WhatsApp, anyone hijacking the agent could use all of those permissions. The precondition is malicious code already running on the computer. Meta fixed it on September 22 by removing the setting, calling it a local rather than remote attack with low risk. Wardle argues that common tricks which get users to run malicious commands make that precondition easy to meet.

Sources

  1. Patrick Wardle, post on X disclosing the flaw, (x.com)
  2. Meta (David Singleton), post on X with Meta's statement, (x.com)
  3. Gizmodo, “Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistant”, (gizmodo.com)
  4. InfoQ, “Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client”, (infoq.com)

About this story

This story was posted on Instagram by @jarrus.tech on Sept. 29, 2026.

Spotted an error in this story? [email protected] · Instagram

This story in Turkish: Meta, Muse’da e-postalara ve dosyalara erişimin yolunu açabilen bir güvenlik açığını kapattı

On the same topic