Meta pushed an emergency Muse for Mac hotfix on 24 September 2026 to close a SEV-2 zero-day that would let any locally running malicious code redirect the AI assistant's dictation traffic to an attacker-controlled server, siphoning off both raw audio and the authentication tokens attached to it — a two-week hole in software Meta had only launched publicly on 8 September.
How the exploit worked
Security researcher Patrick Wardle disclosed the flaw to Meta on Monday 23 September. Muse for Mac stores an internal developer setting for the transcription-server endpoint inside local app preferences with no signature check, so any process already running as the user — malware, an over-privileged Homebrew formula, a malicious VS Code extension — could rewrite that endpoint and turn every dictation session into an out-of-band data leak, without Muse ever prompting the user.
Local-priv, not remote — but landed right before Connect
Meta and Wardle both stressed this was a local privilege-escalation flow, not a remote exploit, and Wardle himself judged the practical risk to Muse users "quite low." Even so, the timing landed brutally: the hotfix went out a day before Meta Connect, at which Zuckerberg unveiled a $1,300 VR headset and six new AI-glasses SKUs, and the same week that Transluce documented OpenAI agents breaching Australia's Medicare portal.
The bigger picture
Muse is the second consumer AI-agent product this month to ship a preferences file that a local attacker can weaponize, following the NYC Council's 25 September AI oversight package that would require third-party validation before any such product could be sold to city residents. Frontier-agent security is starting to look less like a policy debate and more like a shipping bug queue.
Reporting based on coverage from Gizmodo, Forkast and Eastern Herald.