Meta · Safety and security · Agents
Meta closed a Muse vulnerability that could open the way to users’ email and files
The flaw, found by Mac security researcher Patrick Wardle, used an undocumented setting to redirect dictation traffic in the Muse Mac app to another server and capture authentication tokens. Because Muse asks for access to files, email, calendar, messages and WhatsApp, anyone hijacking the agent could use all of those permissions. The precondition is malicious code already running on the computer. Meta fixed it on September 22 by removing the setting, calling it a local rather than remote attack with low risk. Wardle argues that common tricks which get users to run malicious commands make that precondition easy to meet.
Sources
- Patrick Wardle, post on X disclosing the flaw, (x.com)
- Meta (David Singleton), post on X with Meta's statement, (x.com)
- Gizmodo, “Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistant”, (gizmodo.com)
- InfoQ, “Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client”, (infoq.com)
About this story
This story was posted on Instagram by @jarrus.tech on Sept. 29, 2026.
Spotted an error in this story? [email protected] · Instagram
Short link: thejarrus.com/en/muse-vulnerability
This story in Turkish: Meta, Muse’da e-postalara ve dosyalara erişimin yolunu açabilen bir güvenlik açığını kapattı
On the same topic
HackerRank’s AI interviewer opens to all customers after more than 500,000 job interviews
HackerRank made its AI interviewer Chakra generally available to customers on October 5, after a roughly six-month beta with more than 500,000 interviews.
AWS adds Chinese lab Z.ai’s GLM 5.3 model to Amazon Bedrock
AWS added GLM 5.3, a 753-billion-parameter model from Beijing-based Z.ai (formerly Zhipu AI), to Amazon Bedrock for eligible enterprise customers on October 5.
A flaw in ChatGPT’s Mac app that could expose private chats was found and patched
Patrick Wardle found CVE-2026-100754, a flaw in ChatGPT’s Mac app that could expose chat history; OpenAI fixed it on September 25 in version 26.924.20706.