📣 Send us your press release
Site updates every 15 minutes
Technology

Meta's Muse AI App on macOS Suffered Critical Vulnerability

A macOS security researcher discovered a critical vulnerability in Meta's Muse app, potentially allowing attackers to hijack user accounts and access linked applications.

25 September 2026

Security researcher Patrick Wardle has uncovered a significant zero-day vulnerability in Meta's Muse application for macOS. Dubbed "Not-a-Mused," the flaw could allow attackers to hijack a user's Muse account and leverage its system permissions to access linked applications such as email, calendar, and WhatsApp.

The vulnerability exploited Muse's cloud-based speech processing. Wardle found that a hidden configuration item, endo_voyager_dictation_endpoint, could be modified by a local process or script without triggering additional macOS permission prompts. By redirecting this setting to a controlled server, an attacker could intercept voice commands and authentication tokens, effectively taking control of the logged-in Muse instance.

Meta has released a hotfix to address the issue, removing the problematic debugging voice configuration. David Singleton from Meta Superintelligence Labs confirmed the update addresses the vulnerability by eliminating the configuration setting.

Wardle demonstrated that the exploit did not require sophisticated malware, but could be initiated through social engineering tactics, such as tricking a user into executing a terminal command. This incident highlights ongoing security concerns with AI assistants and their integration with user data and other applications.

Original source: ithome.com