Next upAI x Bio Pitch Contest
News

Meta patches Muse setting that let local malware hijack the AI agent

Meta hot-fixed Muse for macOS after a researcher showed that local malware could redirect dictation traffic and use access granted to the AI agent.

D
Sep 26, 2026 · 2 min read

Meta hot-fixed Muse for macOS after a researcher showed that software already running under a user’s account could redirect the AI agent’s dictation traffic and take control of its interactions.

The change addresses the undocumented endpoint setting used in the attack. Through that setting, local malware could potentially capture dictated audio or prompts, inject new instructions, expose Muse authentication material and act through services the user had connected to the agent.

The patch follows the earlier disclosure of the local Muse vulnerability. The flaw was not, by itself, a way to compromise a Mac remotely. An attacker first needed to get code running as the logged-in user, such as through a separate malware infection or a lure that persuaded the user to run a command.

Security researcher Patrick Wardle’s proof of concept identified the setting, endo_voyager_dictation_endpoint, as a way to replace Muse’s normal transcription destination without elevated privileges. Redirecting that traffic to an attacker-controlled service opened a path to observe prompts and send responses back to the agent. Wardle said the risk was that Muse’s access could become the attacker’s access.

The flaw amplified access rather than providing the initial foothold. Malware operating under a user’s account could potentially reach files, services or other capabilities that the user had authorized for Muse. Wardle’s demonstration implemented only a subset of more than 50 commands exposed by the agent.

The proof of concept targeted the local Mac client rather than Meta’s described cloud virtual-machine architecture. Meta says its agent security design keeps credentials for connected services outside the agent runtime and uses a separate Sentinel process to authorize connector actions and network access.

That separation does not answer how organizations would centrally monitor Muse. Meta’s public security architecture post describes per-user virtual-machine and permission controls, but it does not describe a security-information-and-event-management audit export, an IT administrator console or a data-loss-prevention integration. The absence of those features from that post does not establish that they are unavailable elsewhere.

The opened sources did not identify a Meta security advisory, CVE identifier, affected-version range or fixed build number. They also did not establish active exploitation of the vulnerability.

More news