
Meta patches Muse exploit that let attackers control the AI agent
Image: The VergeJess WeatherbedCloseJess WeatherbedPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Jess Weatherbed is a news writer focused on creative industries, computing, and internet culture. Jess started her career at TechRadar, covering news and hardware reviews.Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. Proof-of-concept attacks developed by Wardle to test the exploit enabled him to take pictures and write malicious files to disk via Muse, which did not alert the user in many cases.“We can manipulate the agent and leverage its privileges to do whatever we want.
- ▪Image: The VergeJess WeatherbedCloseJess WeatherbedPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Jess Weatherbed is a news writer focused on creative industries, computing, and
- ▪Jess started her career at TechRadar, covering news and hardware reviews.Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent.
- ▪Proof-of-concept attacks developed by Wardle to test the exploit enabled him to take pictures and write malicious files to disk via Muse, which did not alert the user in many cases.“We can manipulate the agent and leverage its privileges to
The Verge files mainly under tech. We currently carry 957 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | The Verge |
| Canonical URL | https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent |
| Publication time | 2026-09-22T07:53:58-04:00 |
| Retrieval time | 2026-09-22T11:58:50.951Z |
| Last seen | 2026-09-22T11:58:50.951Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | JkTG15edypvL · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
TechCloseTechPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All TechAICloseAIPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All AINewsCloseNewsPosts from this topic will be added to your daily email digest and your homepage feed.FollowFollowSee All NewsMeta patches Muse exploit that let attackers control the AI agent ‘They should be thinking about security from the very start, and they are just not.’ ‘They should be thinking about security from the very start, and they are just not.’by Jess WeatherbedCloseJess WeatherbedNews ReporterPosts from this author will be added to your daily email digest and your homepage feed.FollowFollowSee All by Jess WeatherbedSep 22, 2026, 11:53 AM…
Excerpt limited to ~120 words for fair-use compliance. The full article is at The Verge.