
Meta patches Muse macOS zero-day enabling local agent takeover
Meta patched a zero-day in Muse for macOS that allowed local takeover of the AI agent. Found by Patrick Wardle, the flaw used an undocumented setting to reroute cloud transcription to an attacker endpoint, yielding account access and enabling silent photo capture and file writes. Exploitation required malicious code already running as the user.
Published