CONFIRMED: the fastest growing app in the US also became a fast target for a security researcher

Muse, Meta's personal agent, passed 2.5 million downloads in just 13 days from launch and took the top spot on the US App Store on September 18, overtaking ChatGPT atop the free apps chart. It is one of the fastest adoption curves ever recorded for a consumer AI agent.

The other half of the story landed days later

Security researcher Patrick Wardle identified a zero day vulnerability in Muse's Mac app. The flaw let a malicious process already running under the user's account, with no special macOS permissions required, redirect Muse's transcription endpoint and capture the agent's authentication token. In practice, malware already on the computer could hijack the assistant's identity.

Meta's response was fast, the underlying warning did not disappear

Meta shipped an emergency fix to the Mac app about 16 hours after disclosure, removing the vulnerable setting from production builds. The speed of the response is a positive, but VentureBeat's coverage highlights a broader problem: corporate security teams still have limited visibility into what an agent like Muse can actually access on the device it runs on.

Why fast adoption amplifies the risk

An agent that gains 2.5 million installs in under two weeks multiplies its attack surface at the same speed. Every user who grants Muse access to a microphone, calendar or files is one more potential target if an authentication flaw appears. The case shows that fast popularity and a fast bug fix do not replace security audits before a mass rollout.

What this means for anyone considering personal agents at work

For a small or midsize company weighing whether to put a consumer AI agent on company machines, the Muse case is a practical reminder: asking what permissions the agent requests, what it accesses locally, and what the vendor's incident response track record looks like should be part of the checklist before adoption, not after an incident.

MaxAssistant's read

Worth separating two metrics the week delivered together: adoption speed and incident response speed. Meta got the second one right, patching quickly once notified. But a zero day this early in the life of a product that already has millions of installs reinforces that explosive growth in personal AI agents remains, at the same time, a product win and an expanding security risk.

Sources

VentureBeat, Meta patched Muse's zero-day, but security teams still lack visibility into what the agent can access: https://venturebeat.com/security/meta-patched-muses-zero-day-but-security-teams-still-lack-visibility-into-what-the-agent-can-access | Gizmodo, Meta Just Patched a Major Zero-Day Vulnerability in Its Muse AI Assistant: https://gizmodo.com/meta-just-patched-a-major-zero-day-vulnerability-in-its-muse-ai-assistant-2000815429 | Ynet, Meta's Muse AI agent raced past ChatGPT in downloads, then a zero-day security flaw emerged: https://www.ynetnews.com/tech-and-digital/article/byjz8ggqgg