Local flaw can redirect Meta Muse macOS dictation
Wardle's not-a-mused PoC shows local code can redirect Meta Muse dictation, exposing prompts and credentials.
Patrick Wardle of Objective-See disclosed a local zero-day in Meta's Muse macOS AI assistant and released a proof of concept named not-a-mused. An unprivileged local process can change the undocumented endo_voyager_dictation_endpoint setting and redirect dictation to an attacker-controlled server, exposing dictated audio, prompts, and authentication material and enabling prompt or instruction injection and abuse of permissions the app already holds. Both sources say the bug does not remotely compromise a clean Mac and needs code already running as the user. The Register describes it as privilege escalation that can undermine Apple's TCC separation and confuse EDR attribution, and says Meta could have used Apple's on-device dictation API; Cyber Security News adds that a hijacked agent could reach files, mail, browsers, purchases, and linked devices. Meta had not publicly responded and no fix was reported, while its bounty offers up to $300,000 for qualifying Muse flaws. The sources disagree on severity wording: one headline claims malware injection, but both bodies describe prompt or instruction injection, not a remote malware-injection flaw.
- Patrick Wardle of Objective-See disclosed a local macOS zero-day in Meta's Muse AI assistant and released a proof of concept named not-a-mused (reports dated 2026-09-21 and 2026-09-22).
- An unprivileged local process can change the undocumented endo_voyager_dictation_endpoint setting and redirect dictation traffic to an attacker-controlled server.
- Redirected traffic can expose dictated audio, prompts, and authentication material and can enable prompt or instruction injection plus misuse of permissions already granted to Muse.
- Both reports say the flaw is not remotely exploitable and requires code already running as the user.
- The Register says the issue acts as privilege escalation for local malware, that broad AI-app access can undermine Apple TCC separation and confuse EDR, and that Meta could have used Apple's on-device dictation API.
- Cyber Security News says a hijacked Muse agent could misuse access to files, mail, browsers, purchases, and linked devices.
- Meta had not publicly responded and no public fix was reported; its bug bounty offers up to $300,000 for qualifying Muse flaws.
- The outlets disagree on framing: Cyber Security News' headline says attackers can inject malware, while both write-ups describe prompt or instruction injection rather than remote malware injection.
Coverage timelineoldest first · each row is one article
- · 5d agoMeta Muse AI app flaw lets local malware redirect dictation traffic
The Register · Security· 58
Researcher Patrick Wardle's PoC shows unprivileged local code can hijack Meta Muse macOS dictation traffic, exposing voice prompts and abusing app access.
- · 5d agoMeta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware
Cyber Security News· 67
A local zero-day in Meta's Muse agent lets existing malware redirect dictation, inject prompts, and steal credentials.