Meta shipped a hotfix for its Muse AI agent on Mac on September 22, 2026, roughly 16 hours after security researcher Patrick Wardle publicly disclosed a zero-day that let unprivileged local processes hijack the assistant's dictation flow.
An undocumented endpoint anyone could set
Wardle found that an undocumented setting called endo_voyager_dictation_endpoint could be modified without elevated privileges. Once switched, activating Muse's microphone would send raw audio, prompts and authentication tokens to an attacker-controlled URL instead of Meta's servers — usable for prompt injection, credential theft and even lateral access to a paired iOS device. "Muse's access can potentially become the attacker's access," Wardle wrote alongside a proof-of-concept posted to GitHub as not-a-mused.
16-hour turnaround, $300K bounty
Meta acknowledged the report at 14:42 UTC on September 21, shipped a client-side patch at 06:36 UTC the following morning, and simultaneously expanded Muse's bug bounty program with rewards of up to $300,000 for future agent-hijack findings. The company reiterated that Muse runs each agent in an isolated systemd-nspawn cell governed by a permission broker it calls Sentinel, and confirmed a Muse Confidential VM release is still on track for later 2026.

Agentic AI's expanding attack surface
The incident lands as Muse pushes deeper into desktop territory. Meta only shipped Muse's Mac app days earlier, following the assistant's debut with its own sandboxed VM and Stripe wallet and a wave of new agent capabilities powered by Muse Spark 1.3. Wardle's exploit is the first real-world reminder that as agent surface areas balloon, so does everything an attacker can do by owning them.
Reporting based on coverage from Unite.AI, Malwarebytes Labs and Gizmodo.
