Mac Researcher Found a Zero-Day in Muse That Could Hand Attackers Full Control of the Account

A security researcher showed how one hidden dictation setting in Meta's Muse Mac app let any local process redirect voice traffic.

Jolly the fluffy mascot examining code on a laptop with a magnifying glass revealing a highlighted vulnerability

Mac Researcher Found a Zero-Day in Muse That Could Hand Attackers Full Control of the Account

An undocumented setting controlling where Muse sends voice dictation could be rewritten by any local process, giving an attacker the account token and everything the agent could touch. Meta removed the setting in a hotfix.

Mac security researcher Patrick Wardle disclosed on September 21 a zero-day vulnerability in Meta’s Muse app for macOS that let any locally installed program or terminal command take over a user’s Muse account, Ars Technica first reported. Wardle, the founder of the Objective-See security foundation, demonstrated that a single hidden setting turned the assistant (one of the most privileged applications on a user’s machine) into what he called the ultimate backdoor.

The flaw centered on an undocumented preference called endo_voyager_dictation_endpoint, which controls the server Muse sends voice dictation to for transcription. Normally that points to Meta’s servers. But any local process, regardless of its macOS permissions, could rewrite the setting to point at an attacker-controlled server instead, with no special privileges and no permission prompt.

Once redirected, the attacker’s server sits between the user and Meta. It can read the dictated audio and prompts and, critically, the authentication token for the Muse account traveling with them. With that token, an attacker gains what Wardle described as complete control of the victim’s Muse account, inheriting the assistant’s permissions over files, the microphone and camera, WhatsApp, email, calendar, and linked iPhone devices. Rather than writing malware that earns each of those permissions one by one, an attacker could simply instruct the already-authorized assistant to act.

“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” He built proof-of-concept attacks, dubbed “not-a-mused,” that wrote malicious files to disk and took photos, “in many cases with no indication to even an alert user.”

How the entry point worked

The vulnerability was not a remote exploit. An attacker first needed code running on the victim’s Mac, but Wardle argued that bar is lower than it sounds. A simple variation of a ClickFix-style attack, the social-engineering technique that tricks people into pasting a terminal command, provides all the initial access needed. From there, changing the dictation endpoint requires only a standard local command.

Wardle attributed the flaw to two design choices. First, Muse sends dictation audio to Meta’s cloud servers even though macOS has long provided secure on-device transcription. Second, the app lets any local process modify its hidden settings freely. “When you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” he said.

That criticism cuts against how Meta positioned the assistant. Chief executive Mark Zuckerberg has said Muse was “built from the ground up for privacy and security.” The app, launched September 8, requests broad access to carry out tasks like booking travel, shopping, and messaging on a user’s behalf.

Meta’s response

David Singleton, a leader at Meta Superintelligence Labs, acknowledged the flaw and framed it as a local privilege escalation rather than a remote exploit. “Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,” he said. “Nonetheless, we have issued a hotfix to the app to address the issue.”

The hotfix removes the setting that allowed the dictation endpoint to be changed, closing the redirection path. According to DeafNews’ coverage of the disclosure, the fix landed roughly twelve hours after Ars Technica’s reporting.

Why it matters

The zero-day is one of several trust questions Muse has faced in its first month. Amazon asked Meta in September to stop allowing the agent to shop on Amazon.com on users’ behalf, saying Meta had not identified itself as an agent and raising concerns about how customer credentials were handled. This week, Reuters reported that Apple will flag AI requests for Mac data after Muse drew complaints, a direct response from the platform owner to the same category of concern.

The pattern matters for anyone running an agent with broad system permissions. A personal assistant that can book, buy, message, and manage files is only as secure as its least-guarded internal setting, which is why Muse’s Sentinel permission layer exists to rule on every action before it leaves your machine. In this case, that setting was an undocumented dictation endpoint that any process on the machine could rewrite. The token it exposed came with every permission the user had ever granted. Mac users on the affected Muse builds should update to the patched version.

Keep reading