Threat · curated 21 Sep 2026
Meta Muse AI app flaw lets local malware redirect dictation traffic
First reported theregister.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
The Muse flaw shows how AI apps that demand broad data and tool access can undermine OS privilege-separation protections, giving ordinary local malware far broader reach — including prompt injection and voice-prompt exfiltration — than it would otherwise have.
Security researcher Patrick Wardle disclosed a local zero-day in Meta's Muse AI assistant macOS app, with a proof-of-concept called not-a-mused, that lets an unprivileged local process modify the undocumented endo_voyager_dictation_endpoint setting to redirect Muse's dictation traffic to an attacker-controlled endpoint. The flaw could expose dictated audio and prompts, enable prompt injection, steal authentication material, and abuse whatever access the user granted Muse — effectively a privilege-escalation issue requiring local code execution.