macOS security researcher Patrick Wardle said a serious zero-day vulnerability, a flaw without a released fix, in Muse, a personal AI agent that manages your Mac, lets local malware or an attacker invisibly hijack the agent.
Wardle said the endo_voyager_dictation_endpoint setting in Muse can be redirected locally without special privileges. After the user clicks the microphone and dictates a prompt, Muse sends the prompt to the attacker’s endpoint.
Wardle said the vulnerability can steal an authentication token and invisibly control Muse directly. He said a local attacker then gets access to the messages, email, and finances to which the user gave Muse access.
Claim check:
- macOS security researcher Patrick Wardle said a serious zero-day vulnerability in Muse lets local malware or an attacker invisibly hijack the agent. (confirmed by the primary source: evidence; «But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.»)
- Wardle said the endo_voyager_dictation_endpoint setting in Muse can be redirected locally without special privileges. (confirmed by the primary source: evidence; «Muse has an undocumented setting: endo_voyager_dictation_endpoint …that can be redirected locally with no special privileges!»)
- Wardle said that after the user clicks the microphone and dictates a prompt, Muse sends the prompt to the attacker’s endpoint. (confirmed by the primary source: evidence; «So when you click 🎙️ and dictate a prompt, Muse sends it to the attacker’s endpoint instead 🤦♂️»)
- Wardle said the vulnerability can steal an authentication token and invisibly control Muse directly. (confirmed by the primary source: evidence; «🔑 Steal your auth token & invisibly control Muse directly»)
- Wardle said a local attacker gets access to the messages, email, and finances to which the user gave Muse access. (confirmed by the primary source: evidence; «Anything you gave Muse access to? Now the (local) attacker has it too: msgs, emails, finances… 💀»)
Publications:
- https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day
- https://wired.com/story/metas-muse-ai-agent-zero-day
Primary sources:
- https://x.com/patrickwardle/status/2102045926474785265?s=20
- https://ai.meta.com/muse
- https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse
- https://meta.com/help/artificial-intelligence/1047255454427887
score 62.8 out of 100 · kind: incident · update 2