Meta has released a patch for its Muse macOS app after security researcher Patrick Wardle disclosed a zero-day vulnerability that let unprivileged local processes redirect the assistant's dictation traffic to attacker-controlled endpoints. The flaw, detailed on September 21, involved an undocumented setting called endo_voyager_dictation_endpoint that could be modified without special privileges, potentially exposing dictated audio, prompts sent to Meta's backend AI, and authentication material.
Wardle, founder of nonprofit Objective-See, described the bug as a local privilege escalation that breaks the security boundaries Apple has built through its Transparency, Consent, and Control (TCC) framework. “Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments,” Wardle told The Register, likening the vulnerability to a tenant gaining access to other units.
The Verge confirmed on September 22 that Meta had issued a fix addressing the issue. The patch follows a rocky launch for Muse, which Meta CEO Mark Zuckerberg had hyped as “built from the ground up for privacy and security.” Ars Technica reported that Amazon began blocking Muse from its site on Sunday, before the patch was released.
Muse, launched a few weeks ago, is an AI assistant that books appointments, fills forms, makes purchases, and connects with WhatsApp, email, calendar, and social media accounts. To function, it requires extensive macOS permissions — including file write access, mic and camera use, and location monitoring — that Apple's security framework normally restricts. Wardle argued that the company's decision to process dictation in the cloud rather than using Apple's on-device service unnecessarily widened the attack surface. “I think some of their greediness for user data kind of opens the door,” he said.
Meta did not immediately respond to requests for comment before the patch was issued.