Researcher Discovered Vulnerability in Meta Muse
A flaw in the macOS app allows local malware to reroute sensitive dictation traffic to unauthorized servers.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust AI applications to handle your personal data without compromising your computer's security?
Security researcher Patrick Wardle has identified a zero-day vulnerability in Meta's Muse AI assistant for macOS. The flaw permits local malware to hijack dictation data by modifying an undocumented application setting.
Why it matters
The vulnerability transforms the Muse application into a vector for data theft, potentially exposing sensitive authentication materials and user prompts to unauthorized third parties.
The flaw centers on the undocumented endo_voyager_dictation_endpoint setting, which an attacker with local code execution privileges can modify without elevated permissions. This allows for the redirection of audio traffic to an attacker-controlled endpoint rather than the intended backend model.
The players
Patrick Wardle
A security researcher focused on macOS vulnerabilities and endpoint security.
Meta
A technology company developing AI models and the Muse assistant application for macOS.
The details
The attack mechanism relies on exploiting the Muse application's configuration settings to facilitate prompt injection and credential theft. Because the application fails to protect this specific parameter from modification by local processes, pre-existing malware on a user's device can alter the endpoint. This effectively turns a standard AI assistant into a bridge for exfiltrating audio and prompts, as the application trusts the modified setting to route its traffic.
Timeline
September 2026: Meta launched the Muse AI assistant application.
The Tech Race
This flaw highlights the emerging security challenges inherent in the rapid deployment of integrated AI assistants on desktop operating systems. The incident positions the Muse application as a primary target for researchers investigating how AI model wrappers interact with local macOS configurations.
Users of the Muse application on macOS are at risk if their system has already been compromised by local malware capable of modifying application settings. While the flaw requires local access, those using the software should be aware that unauthorized dictation redirection is technically possible.
The takeaway
This discovery underscores the necessity of auditing configuration endpoints in AI-integrated software to prevent unauthorized data redirection. Users should monitor for official updates or patches from Meta that address the security of the endo_voyager_dictation_endpoint setting.
Further reading
For more on the current state of software safety, see our latest coverage in Cybersecurity.
Live Poll
Do you trust AI applications to handle your personal data without compromising your computer's security?









