Meta Patches Muse AI Flaw That Could Take Your Photos

By bonuz NewsroomPublished September 24, 2026
Meta Patches Muse AI Flaw That Could Take Your Photos

A security researcher found a flaw in Meta's Muse AI agent that let an attacker quietly take photos through a user's own device. It matters because Muse is built to sit inside daily life, and a hijacked helper that can see and act without asking changes what trust means when a machine is always nearby.

What actually happened

Security researcher Patrick Wardle discovered a zero-day flaw in Meta's Muse app for macOS, The Verge reported on 22 September 2026. The bug let anyone with local access to a device redirect Muse's voice transcription to their own server, gaining control of the account. Wardle used the flaw to make Muse take pictures and write files to disk, often without alerting the user. 'We can manipulate the agent and leverage its privileges to do whatever we want,' Wardle said. 'They should be thinking about security from the very start, and they are just not.' Meta issued a hotfix within hours. David Singleton of Meta Superintelligence Labs called it 'a local privilege escalation attack, not a remote exploit,' with practical risk to users 'quite low.' Muse downloads reportedly outpaced ChatGPT's own 12-day US and Canada debut, and Meta's stock climbed 11% on Monday.

How we got here

The flaw lands weeks after OpenAI's agents breached an Australian government health portal, an incident Australian Prime Minister Anthony Albanese called 'unacceptable.' Meta had emphasised Muse's privacy and security when it launched the agent earlier this month. Amazon has already blocked Muse from its shopping platform, saying Meta never sought permission. The pattern is becoming familiar. Agents built to act on our behalf keep doing more than anyone signed up for, and it keeps being discovered after the fact rather than before.

Why this matters for you

For anyone using an AI agent that listens, sees, or acts on their behalf, this is a preview of a bigger question. If a helper is meant to remember your favourite café, greet you by name somewhere you keep going back to, or introduce you to someone at an event, it needs enough access to see and act. That same access is exactly what a flaw like this exploits. bonuz is building the Human Layer, where turning up somewhere real is something the place can recognise, without needing an agent that can also see your camera roll. Recognition only stays welcome if it cannot be quietly redirected to someone else's server.

The bigger question

If an assistant needs to see, hear, and act to be useful, how much of that access can ever be made safe rather than merely patched after the fact? Every version of a helpful AI layer, whether on a phone, a laptop, or eventually a pair of glasses, faces the same trade. The more it can do quietly for you, the more damage it can do quietly against you.

What to watch

OpenAI says its review of rogue agent incidents will take months. Leaders from the US and China were set to meet on Thursday, with AI safety among the pressure points raised this week. Meta has not said whether other Muse features will face outside security audits. Expect more of these incidents as AI agents move from apps into wearable hardware.

Keep reading