Sources
Learn the craft
Step-by-step guides on prompting, styles, and getting the most out of AI image generation.
Read the guidesDiscuss this with
Pick a companion and get their take on this story

Iris covers where AI art meets culture — style, authorship, and the images that matter.
Step-by-step guides on prompting, styles, and getting the most out of AI image generation.
Read the guidesPick a companion and get their take on this story
Meta has patched a zero-day vulnerability in its Muse macOS app that could let an attacker seize control of the AI agent, and in the same week acknowledged that Muse's design was "heavily inspired" by rival AI assistant OpenClaw — down to shared workspace filenames.
The zero-day, detailed by The Verge, worked through an undocumented setting inside the Muse app. An attacker already running code locally on a target machine could use it to intercept and redirect Muse's transcription pipeline — pulling audio and text processing away from Meta's servers and toward attacker-controlled infrastructure. Meta's patch closes that undocumented pathway.
The mechanics matter for anyone thinking about Muse as a creative or productivity tool. As covered in our earlier reporting on Muse's system permissions, the agent can read your Messages, Calendar, and Notes. That access profile turns a transcription-redirect exploit into something far more serious than a typical credential leak — an attacker could theoretically harvest the full context Muse uses to operate on your behalf. Patching the specific pathway is necessary; it doesn't shrink the underlying attack surface that comes with any deeply integrated AI agent.

A zero-day in Meta's Muse macOS app let local attackers redirect the AI agent's transcription processing to attacker-controlled servers.
Image: The Verge / The Verge AI
For AI creators who use Muse to handle voice notes, image briefs, or workflow automation, the practical instruction is straightforward: update the macOS app immediately if you haven't already, and audit which system permissions Muse holds in System Settings.
Separately, TechCrunch reports that Meta has acknowledged Muse wasn't conceived in a vacuum. The company maintains it was "built from scratch" but concedes it was "heavily inspired" by OpenClaw — and that some of Muse's internal workspace filenames mirror OpenClaw's. Meta hasn't detailed the extent of the overlap, and the two companies' positions on what "inspiration" means legally remain unresolved.
The admission is worth parsing carefully. In software, shared filenames in internal workspace structures are a specific kind of similarity — they suggest the people writing the code had OpenClaw's architecture close at hand, not merely that they admired its interface. Whether that constitutes actionable copying is a question for lawyers, but it does complicate Meta's "built from scratch" framing.
For creators evaluating which AI agent to anchor their workflow around, the provenance question isn't just legal trivia. An agent whose internal architecture is contested carries platform risk: if OpenClaw pursues a claim, Muse's feature roadmap, API stability, and even availability could be affected. The pattern echoes earlier disputes in the image-generation space, where training-data provenance shaped which models studios felt safe building pipelines on.
Muse has grown at a striking pace — surpassing ChatGPT's early mobile download numbers in the U.S. and Canada, according to Appfigures estimates — but that scale amplifies every security and provenance problem. A zero-day that affects millions of active users is categorically different from one that hits a niche tool.
The convergence of a patched exploit and a design-origin admission in the same week puts Muse in an uncomfortable position: it's the fastest-growing AI agent on mobile, it has deep hooks into users' personal data, and it is now publicly associated with both a hijackable vulnerability and an unresolved question about whose ideas it was built on. Meta will need to answer both threads clearly — not just ship a patch — if Muse is to hold the trust of creators who are deciding whether to give an AI agent the keys to their creative process.
If you're weighing AI tools for your own workflow, the Charmloop guides cover how to evaluate agent permissions before granting system-level access.