Meta Muse Hit by Zero-Day Exploit as Human-in-the-Loop Testing Sparks Privacy Controversy
nashnova research
Meta's AI agent Muse faced two independent incidents — a zero-day vulnerability that could redirect voice data to attackers and a secret test using human contractors to impersonate the AI on phone calls — exposing the risks of granting broad permissions to an AI agent.
What is Muse, and why does it hold so many permissions?
Muse is an AI agent Meta launched in early September 2026. It can book appointments, fill out forms, shop, and create documents on a user's behalf.
To do all that, it needs access to files, microphone, camera, location data, and calendar — nearly every sensitive resource on a phone or computer.
This means → Muse is not an ordinary app. Its permissions amount to a master key ring; if the agent itself is compromised, every door swings open.
What was the zero-day, and how bad could it get?
Patrick Wardle, founder of security research firm Objective-See, discovered a zero-day vulnerability — a flaw present at launch before the vendor has issued a fix — in Muse's macOS version.
The attack: malicious code running locally could alter Muse's configuration file and redirect voice-dictation data to an attacker-controlled server. Exposed data included voice content, input prompts, and authentication tokens.
The barrier to exploitation was not high: an attacker only needed to trick the user into running a specific command. Meta said it shipped a hotfix on September 22.
Why are AI agents more dangerous than ordinary apps?
Wardle pointed out that an AI agent's broad access across applications undermines the isolation barriers macOS security mechanisms normally enforce between apps.
In plain terms = traditional apps each stay in their own lane; the OS builds walls between them. An AI agent, to get things done for the user, must pass through multiple walls at once. Once the agent is compromised, the attacker inherits all those passages.
This reflects a deeper tension: the more useful an AI agent becomes, the more permissions it needs — and the greater the damage when it is breached.
What happened with humans impersonating the AI on calls?
Reuters reported a separate incident: Meta tested having human contractors make phone calls in place of Muse, because some merchants hung up after realizing they were talking to an AI.
The contractors handled bookings, inventory checks, and price inquiries. Internal tests showed a success rate of 95% to 98%.
This means → users believed they were interacting with an AI, but a real person was on the other end — and those contractors could access sensitive information originally meant only for the AI to process.
How did Meta respond, and is the problem solved?
On the zero-day front, Meta shipped a hotfix on September 22, closing the technical gap.
On the human stand-in test, Meta paused the experiment after employees raised concerns. It acknowledged the test was designed to identify safety and privacy issues but failed to adequately disclose the human involvement.
In plain terms = a patch can fix a vulnerability, but it cannot fix an institutional gap. As Muse takes on increasingly critical tasks, permission governance and transparency disclosure will be challenges Meta must address for the long term.
市场有风险,内容仅供研究参考,不构成投资建议。
