Meta's Muse AI agent for Mac had a 0-day letting any local app redirect voice data
Security researcher Patrick Wardle discovered that any app or Terminal command running on a Mac could silently alter undocumented settings in Meta's new Muse AI agent without requiring special macOS permissions. One affected setting, endo_voyager_dictation_endpoint, determines where a user's dictated voice prompts are transmitted, meaning an attacker could reroute that data elsewhere. The flaw surfaced just weeks after Meta heavily promoted Muse's security architecture, including a dedicated Secure VM, a monitoring system called Sentinel, and bug bounties up to $300,000.
Muse is designed to act on users' behalf across apps and accounts—sending emails, filling forms, and making payments—so it requires broad system access, making any permission gap especially dangerous. The discovery undercuts Meta's public assurances, including Mark Zuckerberg's claim the agent was 'built from the ground up for privacy and security,' raising questions about how thoroughly AI agents with deep system access are vetted before release.
- Muse, Meta's personal AI agent, launched on Mac with broad permissions to act across apps and accounts.
- Researcher Patrick Wardle found any local app or Terminal command could alter undocumented Muse settings without macOS permission checks.
- The bug could redirect dictated voice prompts, contradicting Meta's heavy marketing of Muse's security safeguards.
Source: 9to5mac.com — Arin Waichulis, 2026-09-22
Published there as: “Security Bite: The last 24 hours at Meta were “not-a-musing””
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.