Skip to content
← All news
4 min read

A researcher found a 0-day in Meta's Muse agent 13 days after launch

Patrick Wardle found an undocumented setting that any unprivileged process can rewrite, pointing Muse's dictation traffic at a server the attacker controls.

Muse shipped on September 8. On September 21 a Mac researcher published a working exploit and a repo.

Meta shipped Muse, its personal AI agent, on September 8, 2026. Thirteen days later Patrick Wardle, founder of the Objective-See Foundation and a long-time macOS security researcher, published a zero-day in the Mac build along with a working proof of concept he named not-a-mused. The repository went up on September 21. Meta has not published a patch.

The flaw is a configuration value, not a memory bug. iTnews reported that Muse reads an undocumented setting named endo_voyager_dictation_endpoint, and that any local process running as the user can rewrite it without elevated permissions. Change the value and Muse sends its dictation traffic somewhere else. From there an attacker can capture spoken prompts before they reach Meta, alter the instructions the agent acts on, and collect authentication material tied to the account.

What it needs, and what it gets

This is not a remote attack on a clean Mac. Something has to already be running as the local user, through ordinary malware or a social-engineering step. Wardle's argument is that this is exactly the point. Malware that lands on macOS is normally boxed in by the platform's privacy controls: no microphone, no camera, no calendar, no files, until the user clicks through a prompt for each one. Muse has already been granted all of it.

So the flaw is an amplifier. A process with almost no reach borrows the reach of a process the user deliberately trusted. Wardle's own advice, quoted by iTnews, is blunt: "Please don't install," and he describes it as trivial to turn Muse into the ultimate backdoor. Ars Technica's writeup calls Muse extraordinarily privileged, which is a description of the design rather than the bug.

What is not established

Several things are open. Public reporting does not establish whether Wardle gave Meta advance notice, and Meta has not issued a statement or a fix date that we could find as of September 22. Coverage differs on how far the access reaches: at least one outlet reports the flaw can extend to a linked iPhone, and that claim is thinner than the core finding, which the proof of concept demonstrates directly. Treat the dictation redirect as confirmed and the rest as reported.

Why a build studio cares

We ship custom agents, and this is the failure mode we keep pointing at in audits: the permission a user grants an agent is not a permission, it is a transferable capability. Nobody audits a preferences key. Meta's own threat model clearly did not treat that string as security-relevant, because a security-relevant string does not sit in a file that any process on the box can write. When we look at an agent build now, the question is not just what the agent can do, it is what else on that machine can quietly change where the agent points. A microphone grant that survives being retargeted is not a grant to Muse, it is a grant to whoever edits that file last.

Next step: read Ars Technica's report and Wardle's proof of concept. If you have an agent running on employee machines and nobody has checked what its config surface exposes, that is a Surface Audit question. Write to us at hello@gattyworks.com.

MetaAI AgentsmacOSSecurityMetaMusePatrickWardleZeroDaymacOSAIAgentsAgentSecurityInfoSecAppSecPromptInjection

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call