// 1 CRITICAL · 5 ZERO-DAY · 5 CVE · 2 EXPLOIT IN THE LAST 24H→
Patrick Wardle discovered a zero-day in Meta's Muse AI agent for macOS. An undocumented setting, `endo_voyager_dictation_endpoint`, lets any local process hijack dictation traffic to attacker-controlled servers. No remote exploit is required — just malware already on the machine or social-engineering techniques like ClickFix — to turn Meta's most privileged AI agent into an unlimited access channel to files, connected accounts, and linked devices.

Patrick Wardle, founder of Objective-See, published the discovery of a zero-day vulnerability in Meta's Muse AI assistant for macOS on September 21, 2026. An undocumented setting, endo_voyager_dictation_endpoint, allows any local process without elevated privileges to redirect dictation traffic to attacker-controlled servers. The flaw requires no remote exploit: pre-existing malware on the machine, or social-engineering techniques such as ClickFix, is enough to turn the most privileged AI agent in the Meta ecosystem into an unlimited access channel to files, connected accounts, and linked devices.

Key Takeaways
  • The endo_voyager_dictation_endpoint setting is writable by any local process without privilege elevation on macOS.
  • The redirection enables interception of dictated prompts, injection of malicious instructions, and theft of Muse account authentication tokens.
  • With the stolen token, the attacker operates Muse directly, inheriting permissions over files, microphone, camera, WhatsApp, email, calendar, and linked iPhone devices.
  • Meta released a hotfix removing the dictation setting from production builds roughly 12 hours after Ars Technica's publication.

The Mechanism: A Preference Key That Breaks the TCC Boundary

The technical core of the vulnerability lies in how Muse handles its dictation endpoint configuration. On macOS, the TCC (Transparency, Consent, and Control) system verifies which application accesses the microphone, but does not control where that data is subsequently transmitted. Wardle found that endo_voyager_dictation_endpoint is stored in an unprotected preference file, modifiable by any process running with the logged-in user's privileges.

The change is immediate and requires no administrative password. Once the endpoint is altered, Muse sends dictated audio and text to the attacker's server instead of Meta's. The attacker receives prompt content, can inject manipulated responses, and — critically — intercept the session token that authenticates the Muse account. According to Wardle's published technical documentation, this token enables full control of the assistant, with access to chat history and the entirety of exposed functions.

The Proof-of-Concept published on GitHub under the name not-a-mused implements a subset of the 50+ commands Muse exposes through its local interface. The figure, cited by Wardle in the repository description, indicates the extended attack surface: this is not a single compromised function, but a command architecture amplified by cross-service permissions.

The Attack Chain: From Local Process to Cross-Device Control

Wardle demonstrated that compromise is not confined to the Mac. With the stolen token, the attacker can issue commands to Muse on any device linked to the account. In the demonstration documented by The Hacker News, this included requesting geolocation and Bluetooth scanning on a paired iPhone. The pivot from compromised macOS client to controlled mobile device occurs through Meta's synchronization infrastructure, not via additional exploits on the phone.

The initial entry vector remains bound to local execution of malicious code. Ars Technica specifies that the vulnerability does not provide remote code execution: it requires pre-existing malware or payload execution through social-engineering techniques like ClickFix. This distinction is relevant for risk assessment, but does not mitigate the severity of the flaw. An infected process with user privileges — the standard for the vast majority of consumer malware — has all the requirements for the attack.

"We can manipulate the agent and leverage its privileges to do whatever we want. So instead of having to write complex macOS malware, we can just leverage the AI assistant itself."
— Patrick Wardle, via Ars Technica

Meta's Response: Hotfix in 12 Hours and a Contested Assessment

Meta removed the endo_voyager_dictation_endpoint setting from production builds via a hotfix released approximately 12 hours after Ars Technica's investigation was published. CPO Magazine and The Verge confirm the intervention, though with slightly different temporal phrasing: the former says the hotfix was "released," the latter says the patch arrived "in the hours following" the report. None of the sources document technical details of the fix beyond the removal of the setting.

David Singleton of Meta Superintelligence Labs characterized the flaw as a "local privilege escalation attack, not a remote exploit," adding that "the practical risk to users of the Muse Mac app was therefore quite low." The assessment, published by The Verge, contrasts with Wardle's analysis, which called the technique "trivial to turn Muse into the ultimate backdoor." The discrepancy reflects a structural divergence in how AI agent security is conceived: Meta measures risk based on the entry vector, Wardle on the amplification potential once local access is obtained.

An additional context element emerges from the disclosure conditions. Wardle did not report the vulnerability to Meta before publication, opting for full disclosure to accelerate the fix. This choice, documented by The Hacker News, raises questions about the functioning of Meta's bug bounty program for Muse, which according to official company materials provides rewards up to $300,000 for security flaws and up to $130,000 for prompt injection attempts with single-user impact. No source confirms whether Meta intends to award a bounty despite the absence of a prior report.

Commercial Context and Friction with Amazon

The discovery comes at a moment of high visibility for Muse. According to The Verge, Meta's stock rose 11 percent the Monday following the assistant's launch, indicating the product is perceived as strategic by market analysis. Simultaneously, Amazon blocked Muse from its platform before public disclosure, citing violation of Terms of Use. Ars Technica reports the episode without clarifying whether the block was specifically informed of the vulnerability in confidence or represented an independent commercial matter. The dossier does not resolve this uncertainty.

The tension between marketing positioning and attack-surface reality also surfaced in Meta's official statements. The ai.meta.com site describes Muse as "built from the ground up for privacy and security" with a Secure VM architecture, while the company's research blog details the Sentinel permission system and the concept of "tainted egress" to limit sensitive data exfiltration. None of these pre-disclosure documents acknowledge the flaw identified by Wardle or anticipate its dynamics.

What to Do Now

For organizations that have deployed Muse on macOS endpoints, the actions documented by sources are limited to the following:

  • Verify that the Muse app is updated to the production build after September 21, 2026, containing the removal of the endo_voyager_dictation_endpoint setting.
  • Review linked iPhone devices and accounts connected to Muse for anomalous activity in the period before the hotfix, given the demonstrated cross-device abuse with a stolen token.
  • Evaluate revocation and regeneration of Muse session tokens on exposed enterprise profiles, if the functionality is supported by account administration.
  • Integrate the presence of AI agents like Muse into privileged asset inventories, recognizing that signed, user-approved applications can host vulnerable configurations undetectable by traditional endpoint detection tools.

Why Redefine Least-Privilege for AI Agents

The lesson of the Muse case goes beyond the single flaw. The agentic architecture — where an application unifies access to dozens of services and devices through a conversational interface — inherits and amplifies traditional operating system security gaps. The problem is not that macOS allows a user process to modify a preference file: it is that this capability, trivial and legitimate in other contexts, translates into total control of an agent with cross-service and cross-device permissions.

Perimeter defenses based on application reputation — digital signature, notarization, TCC for microphone — do not intercept post-consent manipulation. Endpoint detection, configured to flag suspicious processes, does not detect anomalous activity when the legitimate process is the signed AI assistant itself. Wardle demonstrated that the attacker does not need to develop sophisticated malware: they can delegate exfiltration, control, and lateral movement to Muse, exploiting the trust the operating system and the user have granted the agent.

For security teams, this demands a shift in register. Least-privilege can no longer stop at the human user or the cloud service: it must extend to tokens, exposed commands, and the reactive capabilities of every deployed AI agent. The attack surface is no longer the sum of individual connected applications, but the product of their interactions mediated by a single conversational entity. The Muse case is the first large-scale documented example of how this concentration of trust can be weaponized through the most trivial configuration.

Frequently Asked Questions

Does the vulnerability require physical access to the Mac?
No. It requires local code execution with user privileges, obtainable via malware or social-engineering techniques like ClickFix, not necessarily physical access.
Has a CVSS classification or CVE been assigned?
No CVE had been assigned as of September 22, 2026, according to the explicit table published by Tech Insider. No subsequent source documents the assignment of an identifier or score.
Is Meta's hotfix sufficient to mitigate the risk?
The hotfix removes the vulnerable setting, but the dossier does not document independent analyses of the fix's completeness or potential variants of the same mechanism.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. cpomagazine.com
  2. arstechnica.com
  3. cybersecuritynews.com
  4. tech-insider.org
  5. theverge.com
  6. malwarebytes.com
  7. thehackernews.com
  8. github.com
  9. nowsecure.com
  10. ai.meta.com
  11. research.meta.ai