TLDRocket
Sign in

Researcher finds a Muse token-exposure path via a macOS debug setting; Meta patched by Sept. 22

unite.ai ● Covered by 2 sources

A researcher found a Mac bug in Meta’s new Muse agent that could reroute dictation to an attacker. Meta says it hot-fixed it fast, but the flaw could expose tokens, messages, and more.

Based on reporting by unite.ai — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Security researcher Patrick Wardle says Meta has already patched a zero-day in Muse, the company’s newly launched personal AI agent, after he disclosed it on September 21, 2026. The issue was ugly in a very specific way: a local process with no special privileges could change an undocumented setting and quietly send Muse’s dictation traffic somewhere else.

Wardle posted his findings on X, then followed them with a proof of concept on GitHub called “not-a-mused.” The repository’s history shows the work landing on September 21: the title and description were added, the script was created, and the README was updated. By the next morning, he was back on X saying, essentially, that the patch had landed and he was happy about how quickly it happened.

The flaw sits in a setting called endo_voyager_dictation_endpoint. When a user taps Muse’s microphone button and speaks a prompt, the app can be tricked into sending that dictation to an attacker-controlled endpoint instead. Wardle said the consequences could include stolen audio, prompt injection, theft of Muse authentication material, and abuse of whatever access the user had already granted the agent. His own summary was blunt: Muse’s access can become the attacker’s access.

That matters because Muse is not just another local app with a small blast radius. Wardle said the proof of concept only needs code execution as the local user, but Muse may have far broader access than ordinary malware would get on its own. He also said a successful hijack could extend to connected devices running Muse, including the mobile iOS client, and later noted that a remote ClickFix-style path existed too, requiring only a single user-run command.

Meta had launched Muse on September 8, 2026 with a security design meant to assume the agent could be under attack. The company said its daemon and tools run inside a systemd-nspawn runtime cell, with Sentinel acting as the permission gate for connector actions and network egress. It also said it would pay up to $300,000 through its bug bounty program, and up to $130,000 for successful prompt-injection reports affecting one user. Wardle’s disclosure is a neat reminder that even systems built around guardrails can still trip over one badly placed switch.

My take — AI-written commentary, not fact-checked reporting

This is the AI security story in miniature: a product sells on control and safety, then gets clipped by a local setting with a mouthful of a name. Meta’s architecture sounds serious on paper, and it may still be better than the usual “trust the model, trust us” approach, but the real world loves one weak link. Open or closed, the lesson is the same: agents are only as safe as their ugliest edge case.

Read more about this at: unite.ai

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.