Researcher finds flaw in Meta’s Muse agent; company says it’s fixed
A vulnerability in Meta’s new personal AI agent, Muse, could have let attackers intercept dictated audio on a Mac and hijack the token the agent uses to act on a user’s behalf, researcher Patrick Wardle said this week. Meta said it fixed the flaw after his report.
· Originally published by ontime+

Key Points
- A cybersecurity researcher reported a vulnerability in Meta's Muse agent that could redirect dictated prompts on Macs.
- Meta said it patched the flaw after the report, with no sign it was ever exploited.
- The case tests how much access personal AI agents should hold over a user's services.
The latest:
A vulnerability in Meta’s new personal AI agent, Muse, could have let attackers intercept dictated audio on a Mac and hijack the token the agent uses to act on a user’s behalf, researcher Patrick Wardle said this week. Meta said it fixed the flaw after his report. There is no indication it was exploited.
Details:
- The researcher: Patrick Wardle, chief executive of the cybersecurity company DoubleYou.io, said he identified the flaw in Muse, Meta’s recently launched personal agent. He disclosed the finding publicly this week, after reporting it to the company.
- The attack chain: Wardle said the vulnerability could allow an attacker to intercept audio a user dictates, feed Muse commands the agent treats as trusted, and capture the token that controls it — along with every service that token unlocks.
- The stakes: Wardle framed the risk in terms of privilege rather than sophistication, telling Business Insider that “Muse itself has far more access and privileges than most malware could ever dream of having.” A personal agent, by design, holds standing permission across a user’s accounts and applications.
- Meta’s response: David Singleton of Meta’s Superintelligence Labs said in a post on X on Tuesday that the company had fixed the flaw following Wardle’s report. Meta did not point to any evidence that the vulnerability had been used against users.
- The caveat: Singleton said an attacker would first need malware already running on the target’s Mac — a condition that, in his framing, means the user is compromised regardless. Only then could the malware redirect Muse’s voice requests and steal the digital key the agent uses to act for its owner.
- What was taken: The token at the center of the finding is what lets Muse operate on a user’s behalf without repeated authorization. Capturing it, by Wardle’s account, hands an attacker the agent’s standing access rather than a single session.
- The wider product line: Muse sits alongside Instinct in Meta’s push into personal AI agents. Both have drawn security and privacy concerns from some early users, who are weighing how much control to hand a system that acts autonomously across their devices.
- Timeline: Wardle went public with the finding this week; Singleton’s acknowledgment came Tuesday. Meta has not published a detailed technical breakdown of the fix or said how long the flaw was present in shipped versions of Muse.
Background:
Personal AI agents differ from chatbots in that they are granted persistent permission to act — opening apps, sending messages, touching accounts. That design is the source of both their appeal and the security questions now following them.
Between the lines:
The dispute here is less about whether the bug existed than about how much it mattered. Meta’s framing rests on the precondition that malware must already sit on the machine. Wardle’s rests on what the agent controls once that precondition is met: an agent with standing access to a user’s services turns an ordinary local compromise into something far broader than it would otherwise be.
What’s next
Whether Meta publishes technical detail on the fix, whether other researchers probe Instinct for comparable token-handling weaknesses, and whether the company changes how Muse stores and scopes its control tokens.