Meta Muse AI App Flaw Exposes Voice Prompts

A flaw in Meta's Muse AI app allowed local malware to redirect dictation traffic. This vulnerability could expose user voice prompts, despite Meta's assurances of user control over their data. The bug potentially allowed unauthorized interception of sensitive audio input intended for the AI. Meta's response to the flaw was not detailed.

Severity: High · Category: Data Exfiltration

Impact: Local malware could redirect and expose user voice prompts and dictation traffic intended for the Meta Muse AI app.

Source: The Register · Sep 21 2026 · Original source

What Happened

A flaw was discovered in Meta's Muse macOS AI assistant app. This local zero-day vulnerability allowed an attacker capable of executing local code to redirect the app's dictation traffic. This redirection could potentially expose dictated audio and prompts intended for the backend AI model.

Timeline

Technical Analysis

Security researcher Patrick Wardle, co-founder of Objective-See, devised a proof-of-concept called "not-a-mused" for the local zero-day in the Muse macOS app. The vulnerability involved an undocumented setting within Muse called `endo_voyager_dictation_endpoint`. An unprivileged local process could modify this setting without requiring special privileges, thereby redirecting Muse's dictation traffic to an attacker-controlled endpoint. Wardle characterized this as a privilege escalation vulnerability, as it grants local malware broader access than it would otherwise have, effectively bypassing macOS's Transparency, Consent, and Control (TCC) framework and privilege separation. He suggested that Meta's choice not to use Apple's on-device local dictation API, presumably to gain access to user data, contributed to the vulnerability.

Impact

The flaw could lead to the exposure of dictated audio and prompts sent to the backend AI model. It also enabled potential prompt injection, the theft of authentication material, and abuse of any access granted to the Muse app by the user. The vulnerability was described as a single point of failure that could break operating system security controls, giving local malware far broader access. David Singleton of Meta Superintelligence Labs stated that the practical risk to users of the Muse Mac app was "quite low" because exploiting it required malicious code already running on the user’s machine under their user account.

Discovery & Response

Security researcher Patrick Wardle discovered the vulnerability and devised a proof-of-concept called "not-a-mused." Following the story's filing, David Singleton of Meta Superintelligence Labs confirmed that the Muse app had been revised to address the vulnerability, and a hotfix was issued.

How Fencio prevents this

Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.

Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.

All incidents