Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

Meta fixes Muse zero-day vulnerability, raises security visibility concerns

Meta's Muse Mac app had a zero-day vulnerability that allowed malware to hijack authentication credentials without special permissions, effectively turning it into a backdoor. Despite a quick patch, โ€ฆ

Meta patched Museโ€™s zero-day, but security teams still lack visibility into what the agent can access
VentureBeat โ€” 22 September 2026
Text:
1 0 0

Patrick Wardle, founder of the Objectiveโ€‘See Foundation and a former NASA and NSA employee, disclosed a zeroโ€‘day vulnerability in Metaโ€™s Muse Mac app on Monday, showing that malware already running under a standard macOS user account could hijack the agentโ€™s authentication material without needing any special system permissions. The flaw let an attacker seize the credentials that Muse uses to communicate with Metaโ€™s security services, effectively turning the legitimate app into a backdoor.

The discovery comes as Muse, Metaโ€™s endpointโ€‘security agent for macOS, has seen rapid adoption, reaching more than 2.5โ€ฏmillion downloads in its first 13โ€ฏdays according to analytics firm Sensor Tower. The app is marketed to businesses and individuals as a way to protect devices from phishing, ransomware and other threats, and its swift uptake reflects growing demand for cloudโ€‘based security solutions on Apple computers. The timing of the disclosure highlights how quickly new security tools can become widespread targets for exploitation, especially when they handle sensitive authentication tokens.

Wardle demonstrated the impact of the flaw by compromising a Muse session and extracting the location of a linked iPhone, which he traced to Barcelona. He then triggered a Bluetooth Low Energy scan from the compromised Mac, showing that the attacker could extend control to nearby devices. The episode underscores a broader problem: security teams often lack visibility into what privileged agents like Muse can access or do once installed, making it difficult to detect malicious misuse of legitimate software.

Meta issued a patch for the vulnerability within hours of the public disclosure, but experts warn that the fix alone does not solve the underlying visibility gap. Organizations are urged to audit the permissions granted to security agents, monitor their network activity, and consider additional controls such as zeroโ€‘trust policies. As more firms rely on thirdโ€‘party security software, the incident serves as a reminder that even trusted tools can become attack vectors if their inner workings remain opaque.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Swiss AI detects natural disaster signs faster than traditiโ€ฆ
๐Ÿ’ป Technology
Swiss AI detects natural disaster signs faster than traditional methods
France 24 ยท 12 days ago
Apple's iPhone 18 Pro camera innovations went well beyond mโ€ฆ
๐Ÿ’ป Technology
Apple's iPhone 18 Pro camera innovations went well beyond megapixels and AI
Engadget ยท 15 days ago
Wardogs, Valheim 1.0 and other new indie games worth checkiโ€ฆ
๐Ÿ’ป Technology
Wardogs, Valheim 1.0 and other new indie games worth checking out
Engadget ยท 12 days ago
Giant caves beneath sinkhole reveal origin of mystery trencโ€ฆ
๐Ÿ”ฌ Science
Giant caves beneath sinkhole reveal origin of mystery trenches that score Australia's Nulโ€ฆ
Live Science ยท 2 days ago
How to get started with Meta's new AI agent, Muse
๐Ÿ’ป Technology
How to get started with Meta's new AI agent, Muse
Engadget ยท 12 days ago
Declassified documents show UK aware of Israeli war crimes โ€ฆ
๐ŸŒ World News
Declassified documents show UK aware of Israeli war crimes for 24 years
Al Jazeera ยท 12 days ago
Full view