Meta Patches Muse AI Flaw Amid Stock Surge
Meta Platforms Inc. issued a security hotfix for its Muse AI assistant as the product's popularity drove a significant surge in company shares.
Meta Platforms Inc. released a hotfix for its Muse AI assistant after security researcher Patrick Wardle discovered a zero-day vulnerability in the macOS application. The flaw allowed attackers with local code execution to redirect transcription processing to their own endpoints, enabling them to hijack user accounts, take photos, and write malicious files to disk without user notification.
Meta characterized the event as a local privilege escalation attack, asserting that the practical risk to users was low because it required malicious code to already be running on the machine. Wardle countered that social engineering could facilitate such attacks. The vulnerability emerged shortly after the September 8 launch of Muse, an autonomous agent designed to manage emails, travel, and purchases.
Despite the security flaw and a move by Amazon to block Muse from its store for violating terms of use, investor optimism drove Meta shares up 11.43% to $741.25 on Monday. The rally followed reports that Muse had overtaken ChatGPT and Claude in iOS download rankings, increasing CEO Pavel Durov's estimated fortune by $25 billion. Meta is expected to showcase Muse-integrated smart glasses at the Meta Connect event on September 23 and 24.