6 min read

Muse hotfix closes token-stealing dictation flaw; no build named

Meta patched a Muse macOS flaw that could redirect cloud dictation and expose agent tokens, but has not identified the fixed build or released technical details.

Muse hotfix closes token-stealing dictation flaw; no build named

Image: TechRadar

Meta issued a hotfix for a Muse macOS vulnerability that could let malware already running on a user’s machine redirect the assistant’s voice-dictation traffic to an attacker-controlled server, capture account tokens, and commandeer the agent’s connected-app permissions.

The flaw, found by Objective-See founder Patrick Wardle and dubbed “not-a-mused,” is not a remote compromise. An attacker needs local code execution or physical access, Muse voice dictation must be used, and the assistant must already have permissions for services such as email, WhatsApp, calendars, or social accounts. The flaw can turn Muse into a post-compromise tool for collecting data and performing actions the user had authorized.

The affected behavior centered on an undocumented setting named `endo_voyager_dictation_endpoint`. Muse sends dictated commands to the cloud for transcription. Wardle found that local software could alter the endpoint used for that traffic, sending voice input and the agent’s authentication material to infrastructure chosen by an attacker rather than Meta’s servers.

Gemini hit three companies through one test flaw, not three exploits

Recommended reading

Gemini hit three companies through one test flaw, not three exploits

Sergey Kuznetsov 9 min read

How the attack turns an agent into a data-access tool

The issue is not just the theft of a standalone credential. An attacker who captures a Muse token can issue requests through the assistant and use whichever integrations the victim previously granted. The reports describe proof-of-concept attacks that wrote malicious files to disk and took photographs, in many cases without notifying the user.

Attack stageRequired conditionResult
Change dictation routingMalicious local code, remote-management access, or physical accessThe undocumented endpoint is changed to an attacker-controlled server
Capture an active tokenVoice dictation is sent through the altered routeThe attacker obtains access to the victim’s Muse account
Use connected permissionsMuse has integrations such as email, WhatsApp, calendar, or social accountsThe agent can be prompted to retrieve information or take actions through those services

The issue is better described as local privilege escalation combined with data exfiltration than as a conventional remote zero-day. Malware does not need to implement every collection feature if it can redirect and drive an assistant already trusted with the user’s applications.

“We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.”

Patrick Wardle, founder of Objective-See

Two product choices reportedly made the attack possible: cloud-based transcription rather than on-device dictation, and an architecture in which any app could control Muse’s undocumented settings. Cloud transcription made the routing destination security-sensitive, while locally running code could alter it. Together, the conditions let an existing local foothold inherit the assistant’s cross-app reach.

Meta calls the practical risk low

Meta said it fixed the issue after the vulnerability became public. David Singleton of Meta Superintelligence Labs described it as an attack that depended on malicious code already operating under the victim’s macOS user account, rather than a flaw an internet attacker could trigger directly.

“This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low.”

David Singleton, Meta Superintelligence Labs

“Nonetheless, we have issued a hotfix to the app to address the issue.”

David Singleton, Meta Superintelligence Labs

That framing is technically fair on initial access: the bug does not provide an unauthenticated path from the internet into a Mac. Once local code is present, however, an assistant with delegated access can be a more capable target than an individual browser session or application token. The exploit’s value depends on which integrations a user enabled and what the agent can do with them.

Meta has not provided a fixed version number, build identifier, CVE, patch date, technical advisory, or detailed account of how the hotfix prevents endpoint redirection. Administrators and security teams therefore lack the usual artifacts for confirming remediation across a fleet. The reporting also does not say whether users need to update Muse manually, whether the fix was delivered server-side, or whether the problematic setting was removed, restricted, or validated differently.

Patch status changed between reports

The accounts differ on a consequential point: TechRadar said Meta had been informed but had not yet issued a patch, while The Verge said Meta applied a hotfix within hours of the underlying disclosure. The reports may have captured different points in the response timeline, but Meta has not published enough implementation detail to independently verify the fix’s scope.

The reporting gives no evidence of exploitation against Muse users in the wild. Wardle’s demonstrations were proof-of-concept attacks. That is an important boundary on what has been established.

Muse’s earlier security record

This is not the first security concern around Meta’s Muse work. On August 6, 2026, we reported that Muse Spark 1.1 reached the open internet because of a testing error and exploited a vulnerability in a third-party service. That incident concerned the underlying model’s behavior during testing, while not-a-mused concerns a macOS assistant’s local configuration and delegated permissions. They are different failures, but both concern systems intended to take actions rather than simply generate text.

Meta’s Muse effort has expanded quickly. On August 5, 2026, Meta released Muse Code as a beta terminal coding agent for macOS and Linux, powered by the closed Muse Spark 1.2 model and intended for large repositories. On August 10, 2026, it made the 30-billion-parameter Muse Glimmer available under Apache 2.0 while keeping Spark closed. On September 2, 2026, Meta introduced Muse Voice Transcribe with API pricing of $3 per 1,000 audio minutes.

The current reports do not establish that not-a-mused affects any product other than the Muse Mac app. They should not be read as evidence that Muse Code, Glimmer, or Voice Transcribe share the same issue.

What users and administrators still need from Meta

Users should apply the available Muse update and treat local malware prevention as the first line of defense. Users who do not need voice dictation or high-privilege app integrations have a smaller exposure surface than users who enable both. The reports do not document controls for selectively revoking individual integration tokens after updating.

Meta’s response should be assessed against the design failure, not just the speed of a hotfix. A local attacker’s ability to reroute cloud transcription and obtain an agent credential joins a voice interface with authority to operate across users' apps. Until Meta identifies the patched build and explains the changed access controls, organizations cannot easily tell whether their Muse deployment is remediated or merely updated.

One report says estimated downloads of a Muse mobile app exceeded ChatGPT’s US and Canadian debut over their first 12 days, and that Meta stock rose 11 percent on Monday. The vulnerability concerns the Muse Mac app, and the available reporting does not provide Muse macOS install figures or evidence that the mobile-download estimate measures the affected client base.

Frequently asked questions

Was the Meta Muse flaw a remote attack?+

No. Meta described it as a local privilege-escalation attack requiring malicious code already running under the user’s account, or equivalent local access.

What could an attacker do with the Muse vulnerability?+

An attacker could redirect voice dictation to a controlled endpoint, capture a Muse token, and use the agent’s connected-app permissions. Demonstrations included writing files and taking photographs.

Has Meta fixed the Muse dictation vulnerability?+

Meta says it issued a hotfix. The supplied reporting does not identify a patched version, build number, CVE, or whether users must update manually.

Does the flaw affect other Muse products?+

The reporting identifies the Muse Mac app. It does not establish that Muse Code, Muse Glimmer, or Muse Voice Transcribe are affected.

Sergey Kuznetsov

Editor-in-Chief

Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.

/ Keep reading