Meta Hot-Fixes Muse Zero-Day That Let Local Apps Hijack Its AI Agent On Mac

An undocumented dictation endpoint in Meta's Muse Mac agent let unprivileged local processes redirect voice traffic to attacker servers. Meta shipped a hotfix roughly 16 hours after Patrick Wardle's disclosure and expanded its bug bounty to $300,000.

Meta Hot-Fixes Muse Zero-Day That Let Local Apps Hijack Its AI Agent On Mac

Meta shipped a hotfix for its Muse AI agent on Mac on September 22, 2026, roughly 16 hours after security researcher Patrick Wardle publicly disclosed a zero-day that let unprivileged local processes hijack the assistant's dictation flow.

An undocumented endpoint anyone could set

Wardle found that an undocumented setting called endo_voyager_dictation_endpoint could be modified without elevated privileges. Once switched, activating Muse's microphone would send raw audio, prompts and authentication tokens to an attacker-controlled URL instead of Meta's servers — usable for prompt injection, credential theft and even lateral access to a paired iOS device. "Muse's access can potentially become the attacker's access," Wardle wrote alongside a proof-of-concept posted to GitHub as not-a-mused.

16-hour turnaround, $300K bounty

Meta acknowledged the report at 14:42 UTC on September 21, shipped a client-side patch at 06:36 UTC the following morning, and simultaneously expanded Muse's bug bounty program with rewards of up to $300,000 for future agent-hijack findings. The company reiterated that Muse runs each agent in an isolated systemd-nspawn cell governed by a permission broker it calls Sentinel, and confirmed a Muse Confidential VM release is still on track for later 2026.

Meta Platforms headquarters in Menlo Park, California

Agentic AI's expanding attack surface

The incident lands as Muse pushes deeper into desktop territory. Meta only shipped Muse's Mac app days earlier, following the assistant's debut with its own sandboxed VM and Stripe wallet and a wave of new agent capabilities powered by Muse Spark 1.3. Wardle's exploit is the first real-world reminder that as agent surface areas balloon, so does everything an attacker can do by owning them.

Reporting based on coverage from Unite.AI, Malwarebytes Labs and Gizmodo.

Category: Cyber Security

Tags: Cybersecurity AI Agents Zero-Day Meta Platforms AI Security

Related Articles