Advisory
Published 2026-09-21
Verified 2026-09-27

Meta Muse macOS AI agent: Wardle “not-a-mused” local 0-day redirects dictation endpoint → agent backdoor

Patrick Wardle (Objective-See) disclosed a local zero-day against Meta’s new Muse macOS AI assistant (PoC “not-a-mused”; Ars Technica 21 Sep 2026; iTnews Australia 22 Sep 2026). An undocumented preference endo_voyager_dictation_endpoint can be changed by any local process without elevation, redirecting Muse dictation to an attacker endpoint for prompt capture/injection and theft of Muse auth material; because Muse holds broad delegated access (files, mic/camera, calendar, linked services/iPhone actions), hijacking amplifies ordinary local malware. No CVE assigned in coverage; Meta had not publicly responded at time of reporting; Amazon separately blocked Muse shopping. Local foothold required (e.g. ClickFix). Primary: Ars Technica; AU wire: iTnews; PoC: github.com/pwardle/not-a-mused.

Product
Meta Muse macOS AI personal agent
Versions
As shipped at disclosure (Sep 2026 US launch window); no vendor fix confirmed in coverage — treat as unpatched 0-day
Exploited in Australia?
unknown
Patch to
Do not install Muse on managed Macs until Meta ships a verified fix; uninstall/pause Muse; revoke connected-account and TCC permissions; rotate Muse-linked credentials if compromise suspected; hunt for unexpected changes to Muse preferences (endo_voyager_dictation_endpoint) and ClickFix-style local execution

Primary: Ars Technica — Muse Meta AI assistant 0-day (Wardle / not-a-mused) · Vendor: Meta — Muse AI assistant · iTnews — don’t install Meta Muse (22 Sep 2026 AU); PoC github.com/pwardle/not-a-mused

ai identity