Meta Patches Muse AI Zero-Day That Allowed Local Malware to Hijack Dictation

Fix issued after security researcher demonstrated privilege escalation; Amazon had already blocked the app

By LineZotpaper
Published
Updated
Read Time2 min
Sources4 outlets
Meta has patched a zero-day vulnerability in its Muse AI assistant for macOS that allowed locally running malware to redirect dictation traffic and potentially take over the assistant's broad account access, just days after Amazon blocked the app from its site.

Meta has released a patch for its Muse macOS app after security researcher Patrick Wardle disclosed a zero-day vulnerability that let unprivileged local processes redirect the assistant's dictation traffic to attacker-controlled endpoints. The flaw, detailed on September 21, involved an undocumented setting called endo_voyager_dictation_endpoint that could be modified without special privileges, potentially exposing dictated audio, prompts sent to Meta's backend AI, and authentication material.

Wardle, founder of nonprofit Objective-See, described the bug as a local privilege escalation that breaks the security boundaries Apple has built through its Transparency, Consent, and Control (TCC) framework. “Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments,” Wardle told The Register, likening the vulnerability to a tenant gaining access to other units.

The Verge confirmed on September 22 that Meta had issued a fix addressing the issue. The patch follows a rocky launch for Muse, which Meta CEO Mark Zuckerberg had hyped as “built from the ground up for privacy and security.” Ars Technica reported that Amazon began blocking Muse from its site on Sunday, before the patch was released.

Muse, launched a few weeks ago, is an AI assistant that books appointments, fills forms, makes purchases, and connects with WhatsApp, email, calendar, and social media accounts. To function, it requires extensive macOS permissions — including file write access, mic and camera use, and location monitoring — that Apple's security framework normally restricts. Wardle argued that the company's decision to process dictation in the cloud rather than using Apple's on-device service unnecessarily widened the attack surface. “I think some of their greediness for user data kind of opens the door,” he said.

Meta did not immediately respond to requests for comment before the patch was issued.

§

Analysis

Why This Matters

  • The vulnerability highlights the tension between AI assistants needing broad system access and existing operating system security controls, potentially eroding years of platform hardening.
  • Amazon's pre-patch block suggests cloud marketplaces are becoming de facto security gatekeepers for AI apps, adding pressure on developers to prioritize security.
  • If local malware can leverage an AI assistant's permissions, the risk for macOS users — long considered relatively safe from malware — increases substantially.

Background

Muse is Meta's entry in the competitive AI assistant space, launched in early September 2026. The app runs exclusively on macOS, which is unusual for a major consumer AI product, and requires users to grant extensive permissions to handle tasks like email, calendaring, and purchases. Apple's TCC framework is designed to prevent exactly this kind of broad access by default, but users must explicitly approve such permissions for Muse. Security researchers have long warned that AI agents with such privileges become single points of failure. Patrick Wardle is a well-known macOS security researcher who has uncovered numerous vulnerabilities in Apple's ecosystem.

Key Perspectives

Meta: Has not explicitly commented on the vulnerability, but issued a patch within a day of disclosure, suggesting they take the issue seriously. The company has positioned Muse as privacy-focused. Security Researchers: Patrick Wardle argues that AI companies are not applying their own bug-finding AI models to their apps, and that privacy is deprioritized in the race to market. He notes that Apple provides a secure on-device dictation API that Meta chose not to use. Critics/Skeptics: Some may note that the exploit requires local access, which limits its practical risk to average users. However, given that malware can already gain local access through phishing or compromised downloads, the vulnerability effectively amplifies the damage any local malware can do.

What to Watch

  • Whether Meta addresses Wardle's broader critique about cloud-based dictation versus on-device processing in future versions.
  • How Amazon and other platforms handle Muse's availability now that the patch is live.
  • Whether other AI assistants with similar permission models face similar vulnerability disclosures in coming weeks.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.