Meta Muse macOS flaw could redirect users’ dictation audio
A security researcher demonstrated that malware already running on a Mac may alter an undocumented Muse setting and send dictation traffic to an attacker-controlled endpoint. The reported proof of concept requires local code execution.
By DoomRadar · Published on DoomRadar . Updated .
Based on two sources with available article excerpts. Source-linked claims are not independent confirmation.
What happened
Researcher Patrick Wardle reported a local zero-day in Meta’s Muse macOS app and developed a proof of concept called not-a-mused. [1]
References for this detail (1)
- Meta Muse AI app flaw lets local malware redirect dictation traffictheregister.com · Recorded source date: Sep 22, 2026, 3:46 AM UTC
The reported vulnerability allows an unprivileged local process to modify the undocumented endo_voyager_dictation_endpoint setting without special privileges. [1]
References for this detail (1)
- Meta Muse AI app flaw lets local malware redirect dictation traffictheregister.com · Recorded source date: Sep 22, 2026, 3:46 AM UTC
Changing that setting could redirect dictation traffic to an attacker-controlled endpoint and potentially expose dictated audio. [1]
References for this detail (1)
- Meta Muse AI app flaw lets local malware redirect dictation traffictheregister.com · Recorded source date: Sep 22, 2026, 3:46 AM UTC
Context from the sources
The report describes Muse as relying on a Secure VM and notes that Meta had emphasized user control and privacy when launching the app. [1]
Explore the sources and reporting timeline
2 source links · 2 domains
These counts describe the references, not independent confirmations. Different outlets can repeat the same original report.
Source timeline
Oldest to newest among the available source dates, not a chronology of the incident. Article publication dates come from the source; other recorded dates may reflect when a link was found.
What this could mean for you
Sensitive dictated audio could be sent to an unauthorized endpoint
Local malware may change Muse’s dictation destination without elevated privileges
Reported basis: [1] · The possible effect is interpretation.
Depends on: An attacker must first execute code on the affected Mac and successfully alter the app setting
Possible consequences, not a forecast. Their relevance depends on your location and the conditions above.
For your country
Choose a country to check how this event could affect you.
What changes the outlook
Risk increases if…
The flaw remains unpatched while malware campaigns gain access to affected Macs.
The app is used for confidential conversations or documents on compromised devices.
Pressure eases if…
Meta releases and users install a fix that blocks unauthorized endpoint changes.
Operating-system or endpoint protections prevent untrusted local code from running.
Still unclear
The sources do not establish how widely the flaw is being exploited or whether Meta has released a fix.
The excerpts do not specify whether the issue affects Muse versions beyond macOS.
Market implications
Market impact
Sources (2)
References for the reported details. Separate links do not necessarily mean independent confirmation.
Available excerpt
Ad biz promises users control while bug could expose voice prompts Meta made much of the security of its AI assistant app Muse at launch…A short excerpt from our source record; open the original for the full article.
Available excerpt
Meta's ambitious personal AI agent is facing its first real security test just weeks after launch.A researcher managed to find a way around the very…A short excerpt from our source record; open the original for the full article.
AI-assisted analysis · . Based on linked headlines and available excerpts. Methodology · Report an error.