TLDRocket
Sign in

Meta patched a macOS vulnerability in its Muse voice dictation feature that could let an unprivileged process redirect dictation traffic to an attacker-controlled endpoint

Security issue Provisional 87% confidence first seen

A security researcher demonstrated that, on macOS, an unprivileged process could modify an undocumented Muse setting to redirect Muse dictation traffic to an attacker-controlled endpoint. Meta later issued a patch to close the zero-day “dictation traffic hijack” path, confirmed by Sept. 22, 2026, reducing the risk of audio/prompt capture and potential misuse after local compromise.

Source coverage

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.