Security researcher Patrick Wardle has disclosed an unpatched zero-day vulnerability in Meta's newly released desktop client for its Muse AI assistant on macOS, enabling locally running software to hijack the application, capture authentication tokens, and reroute voice dictation traffic to attacker-controlled servers.
Security researcher Patrick Wardle, founder of the Objective-See Foundation, has publicly disclosed an unpatched zero-day vulnerability in Meta's recently launched desktop client for Muse on macOS. While Meta CEO Mark Zuckerberg stated that Muse was built from the ground up with privacy and security in mind, the flaw allows locally running processes or shell commands to take control of the application, bypassing standard macOS security boundaries by leveraging permissions the user had previously granted to the assistant.
The vulnerability originates from an undocumented configuration preference key named endo_voyager_dictation_endpoint. On macOS, local processes and scripts executing in an unprivileged user context can overwrite this config value without requiring elevated privileges or triggering system authorization prompts. Normally, this parameter points to the cloud server that processes voice dictation audio. By modifying the setting, an attacker can silently redirect Muse's outbound dictation traffic to a server under their control.
From an exploitation standpoint, the issue compromises both input confidentiality and account credentials. When a user activates dictation, the client sends raw microphone audio along with a valid authentication token for the victim's Muse account to the configured endpoint. Wardle demonstrated that an attacker can operate a proxy server that captures tokens and audio while forwarding legitimate traffic to Meta's servers to avoid detection. With valid session credentials and control over the command pipeline, an attacker can also conduct prompt injection attacks, embedding hidden instructions into voice requests to force the assistant to perform unauthorized background tasks, such as exfiltrating documents or WhatsApp message histories.
Because Meta did not release a formal security advisory or coordinate with a CVE Numbering Authority, the vulnerability currently lacks an official CVE designation.
Analysis
Why This Matters
- The flaw undermines claims that Muse was built with privacy and security as core principles, especially given the sensitive permissions required for an AI assistant (microphone access, file system access, authentication tokens).
- It demonstrates how a single debug setting left exposed in production can erode macOS's trust model, which relies on users granting permissions to trusted apps. Local malware could exploit this to elevate access without additional user consent.
- As Meta pushes into AI-powered desktop assistants, similar vulnerabilities may emerge across other platforms, making this a bellwether for how seriously Meta takes security in its AI products.
Background
Meta's Muse was announced as a standalone AI assistant, competing with offerings from Apple, Google, and OpenAI. The desktop client, released for macOS, grants Muse extensive system permissions to perform tasks like reading files, accessing messages, and processing voice input. The vulnerability was discovered by Patrick Wardle, a well-known macOS security researcher who has previously uncovered flaws in Apple's own operating system and third-party apps. The issue highlights the risks of leaving debugging functionality enabled in production builds, particularly when it can be modified without authentication or privilege elevation.
Key Perspectives
Meta: The company has not yet issued a security advisory or patch, and did not coordinate with a CVE authority. This suggests either unawareness, disagreement about severity, or that a fix is being prepared internally.
Users: Those who have installed the Muse macOS client and granted it permissions such as microphone access, file access, and the ability to interact with Meta's messaging services are directly at risk, particularly if they run other untrusted software.
Security community: This disclosure underscores the importance of auditing AI-powered applications for debug functionality, and highlights the challenge of trusting third-party assistants with broad system permissions.
What to Watch
- Whether Meta issues a security patch or advisory in response to the disclosure.
- If a CVE is assigned and whether other researchers identify similar issues in Muse or other AI assistants.
- Potential for attacks in the wild targeting the vulnerability before a fix is deployed.