Skip to main content
Security IncidentNew

Meta patches Muse zero-day exploit

Meta has released a security patch for its Muse macOS application to fix a zero-day vulnerability discovered by researcher Patrick Wardle. The flaw involved an undocumented application setting that allowed attackers executing local code to gain control of the AI agent and redirect transcription processing away from Meta's servers. Claims are as reported; this summary makes no determination about accuracy or significance.

First detected
Sep 22, 2026
Last updated
Sep 22, 2026

Newly detected

This development was detected recently and reporting may still arrive.

Follow this development to see meaningful updates as new evidence emerges.

Save keeps this for later. Follow tracks meaningful changes as new evidence emerges — it shapes your Following Feed, alerts, and digest eligibility, and doesn't promise an instant notification.

Why it matters

The vulnerability highlights client-side security risks in desktop AI software, where misconfigured or undocumented endpoints can expose user transcriptions and grant control of autonomous agents. Organizations running Muse on macOS must apply the patch immediately to prevent local privilege and data redirection exploits.

Coverage

Primary/vendor sources vs independent reporting

Primary / vendor source: information published directly by the company, organization, government body or project involved. Useful as a primary source, but not independent confirmation.

Independent reporting: reporting or analysis from a source independent of the organization making the underlying claim.

How this developed

  1. Sep 22, 2026

    1. Development detected

    2. New reporting added