Drooid Logo
Back to story perspectives

Full Breakdown

Meta’s Muse AI Agent: Rapid Rise, Open-Source Inspiration, and a Zero-Day Patch

By Drooid · · How we work

Launch and Market Reception

Meta released its personal AI assistant Muse on September 8. Within two weeks the app hit number 1 on the U.S. App Store and was downloaded more than 500,000 times in its first week, with over 250,000 daily users submitting upwards of two million prompts. The uptake helped Meta’s stock climb 11 % in a single day, the biggest one-day gain since April 2025.

Open-Source Inspiration Claims

> “We built muse from scratch, but it is definitely heavily inspired as a product by openclaw. After I used openclaw in january I bought hundreds of mac minis for the MSL team and lots of us fell in love with using openclaw (and other personal agents).” — Nat Friedman, Meta spokesperson

Security Vulnerability Discovered

Security researcher Patrick Wardle, founder of Objective-See, released a proof-of-concept zero-day in Muse’s macOS app. The flaw lets a malicious local process modify an undocumented setting, redirecting dictation traffic to an attacker-controlled server and potentially exposing authentication tokens. Wardle suggested the exploit could be leveraged remotely after a user is compromised, while Meta’s head of Superintelligence Labs, David Singleton, said the bug requires malware already present on the user’s computer.

Official Responses

Meta confirmed the issue and issued a “hotfix” that patched the vulnerable code. Singleton replied to Wardle’s X post, stating the company had addressed the problem and emphasizing that the practical risk to users was low. A Meta spokesperson pointed to Friedman’s earlier statement about OpenClaw inspiration and declined further comment.

Criticism and Privacy Concerns

Wardle warned the vulnerability could enable attackers to capture dictated audio, prompts, and authentication material, amplifying the permissions already granted to Muse. Independent commentary noted that Muse accesses email, calendar, messaging, microphone, camera, location, and file system to perform tasks such as booking reservations or making purchases.

Impact and Implications

The episode highlights two challenges for large-scale AI agents: client-side security and transparency around open-source inspiration. Muse’s rapid adoption shows strong consumer interest, while the zero-day incident demonstrates how a compromised local client can become a high-value attack surface.

Conflicting Reports & Gaps

  • Exploit scope: Wardle argues remote exploitation is possible after initial compromise; Singleton maintains it only works if malware is already on the device.
  • Technical details: Cyberpress describes the vulnerability as requiring local code execution, aligning more closely with Singleton’s view.
  • Mitigation guidance: No formal vendor advisory has been issued yet; users must rely on the hotfix and best practices such as limiting sensitive dictation and enforcing least-privilege permissions.

Verbatim Quotes

  • “We built muse from scratch, but it is definitely heavily inspired as a product by openclaw. After I used openclaw in january I bought hundreds of mac minis for the MSL team and lots of us fell in love with using openclaw (and other personal agents).” — Nat Friedman, Meta spokesperson

What’s Next

Meta has urged users to update the macOS Muse app immediately to obtain the security fix. Ongoing monitoring of Muse’s permission model and any additional vulnerability disclosures will be critical as the agent expands into broader consumer workflows.