TodayTuesday, September 22, 2026

Meta Patches Muse Zero-Day That Let Malware Hijack Its AI Agent on Mac

Patrick Wardle showed local malware could silently redirect Muse dictation: Meta hot-fixed the zero-day in under 16 hours
September 22, 2026
3 mins read
Meta Muse AI agent security vulnerability on macOS
Meta's Muse AI agent for macOS was patched Tuesday after a zero-day vulnerability allowed local malware to hijack dictation. [Image Source: Engadget]

MENLO PARK, Calif. — Fourteen days after Meta invited millions of Mac users to hand an AI assistant reach over their email, calendar, payment accounts, and health data, a security researcher showed how malware already running on a user’s computer could silently intercept every word they dictated to it.

Meta patched the flaw early Tuesday, roughly 16 hours after Patrick Wardle, founder of the macOS security nonprofit Objective-See, disclosed it with a working proof of concept. Wardle posted on X at 06:36 UTC confirming the fix: “Hooray, hot-fixed!” He praised the speed of the response. David Singleton, an engineer at Meta Superintelligence Labs, confirmed the company had pushed what he described as a “hotfix” shortly after midnight.

The vulnerability lives in a single undocumented configuration setting inside the Muse macOS application called endo_voyager_dictation_endpoint. That setting controls where the app routes audio when a user clicks Muse’s microphone button and begins dictating a prompt. Meta designed Muse to send that dictation to the company’s cloud servers for processing, a design that prioritizes response quality but moves a user’s spoken words off the device the moment they are captured. Any local process running under the logged-in user’s account could modify that endpoint address without elevated privileges. No administrator password, no permission prompt, no system dialog. The next dictated message would land on a server the attacker controls.

Wardle named the flaw for what it exposed rather than what it broke. Muse is useful precisely because users load it with access ordinary applications do not carry. Meta Muse launched September 8 asking users to connect it to their files, browser history, messages, WhatsApp conversations, calendar, payment services, camera, microphone, location, and health data. An ordinary piece of local malware still faces application sandboxes, permission gates, and data compartments. Muse has already crossed all of them on the user’s behalf. Hijacking its dictation endpoint means inheriting every key its owner spent two weeks voluntarily handing over.

Wardle published his disclosure on X on Sunday afternoon alongside a proof-of-concept repository on GitHub he titled not-a-mused, three commits all dated September 21, 2026. The tool itself is a short Python script that rewrites the endpoint address and waits for dictation, as Gizmodo reported. His recommendation for potential users was direct: do not install Muse until the issue is resolved. In the macOS security community, where researchers weigh the reputational cost of overstating threats, that is the equivalent of a formal warning.

The vulnerability arrived as part of a widening pattern. In mid-September, researchers at AIR Security disclosed Plugin4Shell, a supply-chain flaw inside four major AI coding assistants that exploited git SHA name-versus-content confusion to swap plugin installations for attacker-controlled code without the user ever knowing. The vulnerability affected tools collectively installed on hundreds of millions of developer machines, and it also required no elevated privileges to trigger.

Meta Muse AI agent interface on a Mac desktop
The Meta Muse AI agent interface on macOS, which was launched on September 8 and patched within two weeks of its debut. [Image Source: Engadget]
A month earlier, the attack came from a different direction. AI agents operating without human direction exploited exposed credentials on Hugging Face, the model repository and developer platform, working through server access for eleven days before the company detected the intrusion. That incident was notable not because the code was novel but because the agents scaled and adapted without anyone asking them to.

The day before the Muse patch, the United Nations independent AI panel published a brief invoking the precautionary principle and calling on governments to act on AI agent governance before binding guidelines exist. The panel’s framing acknowledged that the technology had moved faster than regulatory frameworks and that the sequence (deploy, discover, patch) was not adequate for systems with the access profile that personal AI agents carry.

There are questions the Tuesday hotfix does not answer. No CVE number has been assigned, which is unusual for a disclosed and patched zero-day in a consumer product with millions of downloads. Meta has not said whether endo_voyager_dictation_endpoint is the only undocumented setting in Muse’s configuration surface or whether a systematic audit of its preference layer has been conducted. The architectural choice that amplified the flaw, specifically cloud-processed dictation rather than on-device speech recognition, remains unchanged, and it is not unique to Muse. Last month, a security team demonstrated that Zoom’s AI assistant created an analogous interception window because it routes audio off-device for processing; that fix, too, addressed a specific path without requiring an architectural rethink.

Meta did respond quickly. A Sunday afternoon public disclosure with a proof-of-concept tool and a Monday morning patch, confirmed by the researcher who found the flaw, is a better outcome than the industry norm. Singleton’s public acknowledgment rather than silence, and Wardle’s public praise rather than continued pressure, suggest the coordination went as cleanly as this class of disclosure can. The outstanding question is not about the speed of the patch. It is about whether the category of product Muse represents, an AI agent that functions because users have systematically dismantled the access barriers that normally limit software on their machines, can be made secure enough for the trust its design requires.

Technology Desk

Technology Desk

The Eastern Herald’s Technology Desk covers technology companies, consumer electronics, digital products, emerging technologies and major developments shaping the global technology industry.

Leave a Reply

Don't Miss