The Muse Hotfix Removed a Setting, Not the Blast Radius
Meta shipped a hotfix for its Muse Mac app under fourteen hours after a security researcher published working exploit code, and the researcher thanked them for it. That is a good outcome and a fast one. The uncomfortable part is what the fix had to be: one internal preference key deleted from production builds. The vulnerability was never that a setting existed. It was that the client installed on your machine is the thing holding your account, and the agent on the far end answers to whoever is holding it.
Patrick Wardle, founder of the macOS security nonprofit Objective-See, published a proof of concept he calls not-a-mused on September 21, 2026, describing a local zero-day in the Muse macOS app. His opening post was blunt: “Please don’t install - it’s trivial to turn Muse into the ultimate backdoor”. Ars Technica covered it the same day, and The Register ran it within hours. Meta confirmed a hotfix at 04:07 UTC on September 22, and Wardle replied at 06:36 UTC with praise and a correction.
Muse is not a chat window. Meta’s personal agent, announced by Mark Zuckerberg on September 8, books appointments, fills out forms, sends email, runs your WhatsApp, calendar and social accounts, and makes purchases with a linked card. If a task needs a tool that does not exist, Muse writes one on the spot. Its security story is architectural: every account runs inside an isolated cloud computer called Muse Secure VM, and a separate service called Sentinel is supposed to be the sole authority over which services and which network traffic the agent can reach, swapping in one-time tokens so the agent never handles real credentials. Zuckerberg’s claim was that it is “built from the ground up for privacy and security.”
Thirteen days after launch, a local process with no privileges at all was enough to take the whole thing.
One preference key was the entire attack
The published proof of concept is a single Python file with no dependencies, and its own summary is precise: Muse exposes an undocumented setting, endo_voyager_dictation_endpoint, and “a local attacker or malware can modify this endpoint without special privileges.” Redirected, it allows “capture of dictated audio/prompts, prompt injection into Muse, theft of Muse authentication material, and abuse of whatever access the user has granted Muse.” The repository ends with the line that matters: “Muse’s access can potentially become the attacker’s access.”
Reading the PoC source shows how little scaffolding the attack needs. The tool points the dictation endpoint at a local proxy, restarts Muse, and then sits in the middle of two conversations. Upstream dictation normally goes to wss://shortwave.facebook.com/voyager/v1/asr/duplex. The account API lives at https://hatch-api.meta.ai, with paths /hatch/verify_oauth_token and /hatch/fetch_leased_vm. The gateway into the isolated VM is wss://hatch.metaaivm.com/v1/noise, running a Noise handshake (Noise_XX_25519_AESGCM_SHA256) with the app identifying itself as endo-macos. The captured account token is validated by a simple prefix test, ABRA, and bounded to 4096 characters. The tool prints the transcribed prompts on the way past and can export stored chat history on request.
None of that is a memory-safety bug or a sandbox escape. It is a preference value, in a preferences domain that macOS deliberately allows any process running as the user to write, pointing at a URL that any process can change. Meta’s own description confirms the design: Muse’s dictation “is powered by a server-side speech model,” and the app “shipped with an internal setting that allows the endpoint used by this feature to be redirected to a different URL, which is useful during debugging and development.”
The reach was bigger than the machine
The second half of Wardle’s disclosure is the part that gets skipped, because it is not needed to make the exploit work. It is only needed to understand the impact. Once a Mac is exploited, in his words, “you can interact with any of the users ‘connected’ devices also running Muse,” which means “you remotely task their mobile (iOS) Muse client …invisibly.” His demonstration drove an iPhone: a location lookup and a Bluetooth Low Energy scan, reported separately by Runtimewire as using Muse’s device inventory API to select an online device and invoke a command it advertised.
The repository also notes that Muse exposes more than fifty commands and that the public PoC implements only a subset. So the honest shape of this vulnerability is not a Mac getting compromised. It is a documented inventory of everything on your account, with a command channel, reachable with one token that was sitting in a preference file.
The fix, and the sentence that is the tell
Meta’s response was fast and, on its own terms, accurate. David Singleton wrote that the company had “issued a hotfix to the Muse Mac app,” that this “was a local privilege escalation attack, not a remote exploit,” and that “using it to do harm therefore requires malicious code already running on the user’s machine under their user account,” so “the practical risk to users of the Muse Mac app was therefore quite low.” He explained the endpoint setting, confirmed that “the setting lives in the app’s local preferences, which macOS allows any program running under your user account to modify,” and stated the fix: “Our hotfix removes the endpoint setting from production builds entirely, which closes this vulnerability.”
Two and a half hours later, Wardle accepted the fix and rejected the framing. “Hooray, hot-fixed!” he wrote, before adding: “But there was a ‘remote’ exploit vector: a simple ClickFix attack could deliver the hijack giving a remote attacker complete access then to every victim device running Muse.”
That is the whole argument, and it is worth separating from the bug, because the bug is now closed and the argument is not.
Why “local, not remote” is the wrong axis
ClickFix is a technique that has become remarkably effective at tricking people into infecting their own devices: the attacker presents a plausible error, a fake CAPTCHA, a “verify you are human” step, and instructs the victim to paste a command into Terminal. Ars Technica’s reporting on Muse is explicit that “a simple variation of ClickFix attack … is all that’s required for an attacker to take control of a Muse account.” The attacker’s server then sits between the user and Meta, injects a prompt that invokes a malicious command, for example sending an archive of all WhatsApp messages to the attacker, and walks away with permanent control of the account, because the authentication token flows to the same server.
So the “local” precondition is real in the sense that code must execute under the user’s account, and it is weak in the sense that a single paste is a delivery mechanism, not a security control. The frame that measures exposure by how code arrived on a machine is measuring the wrong quantity. What determines the blast radius is what the arriving code inherits, and Wardle said exactly that to Ars: “We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.”
The same confusion runs through the cloud isolation claim. Meta notes that the flaw “does not involve Muse’s servers or the Secure VM that isolates agent tasks.” That is true, and it is the finding rather than the mitigation. A Secure VM bounds what the agent can do to Meta’s infrastructure. It bounds nothing about what the client can do to you, because the client is redirected before its traffic ever reaches the isolated environment. Isolation is a property of the server boundary. The failing boundary here was the edge between software on your disk and the identity it carries.
The design decisions that produced the attack surface are the ones Wardle called out by name. Muse chose cloud dictation, where Meta can log the audio, over the on-device dictation API Apple has provided for years; had the app used the platform path, this particular attack would not exist. And the app let any process control the full list of undocumented settings, most of them cosmetic and one of them a redirect for the endpoint where your speech is processed. Wardle’s summary to The Register is about incentives rather than skill: “I think some of their greediness for user data kind of opens the door, makes a bigger attack surface.”
The detection story is worse than the exploit. Endpoint tooling on macOS got better largely because code signing is pervasive, so unsigned and unnotarized processes stand out. Hand an agent broad, standing permissions and that signal goes quiet: a command issued by you, a command issued by the agent on your behalf, and a command issued by an attacker who steered the agent’s channel are the same process, doing the same privileged thing, with the same signature. Wardle’s observation is that EDR products were built to spot bad processes, not to adjudicate intent inside a process that is supposed to be doing privileged work.
What operators should change
- Classify the agent client as a credential holder, not a chat app. Muse’s Mac client stores a token that verifies against the account API and leases the VM. That is password-manager-class material, and it should be inventoried, scoped and monitored as such, not treated as app-local state.
- Bind the token to the client and to the action. The cross-device demonstration worked because one token was enough to enumerate devices and invoke commands on them. Cross-device action invocation should require a separate, per-device authorization and a fresh user approval, not a standing account-wide credential.
- Do not downgrade a finding because it needs local code execution. For an agent holding standing permissions across an account, local code execution is an amplification primitive, and ClickFix makes delivery routine. Severity should be assessed on the permissions the agent holds, not on the network distance between attacker and machine.
- Stop relying on process identity for attribution. If your audit trail records “Muse wrote this file” you cannot tell a user instruction from an injected one. Record provenance at the action layer: which model turn, which user approval, which connector, which device.
- Treat redirectable development affordances as production risk. An endpoint override that ships in a writable preferences domain is a standing pivot. Debug switches belong behind a signed configuration, an entitlement, or nothing at all in release builds.
- Keep agent permission footprints narrow, and review them. Wardle’s point is not that agents should have no access, it is that convenience scales with permissions, and so does the blast radius when something goes wrong. A local compromise that would once have been contained to the Mac inherited an agent’s reach across WhatsApp, email, calendar, a payment method and a paired iPhone.
There is a second signal from the same week that belongs next to this one. Amazon started blocking Muse from shopping on its site on the Sunday before the disclosure, roughly twelve hours earlier, showing users a popup stating that “continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed.” Two parties with no connection to each other, a researcher and a retailer, reached the same conclusion inside the same week: nobody could confidently bound what this agent was doing on a user’s behalf, or prove that what it did was the user’s intent.
The hotfix is correct and the speed is creditable. Meta also says a hotfix is the whole answer: the setting is gone from production builds, therefore the vulnerability is closed, therefore the risk was low. Every claim in that sentence is true about the endpoint. The part that is not addressed is the one Wardle built his demonstration on, the one Amazon stepped away from, and the one that will outlive this preference key: the agent client on your machine is an account, and patching a value inside it does not change what it is. Wardle plans to detail the work at Objective by the Sea in November.
Sources:
- Patrick Wardle: not-a-mused proof of concept, GitHub (undocumented
endo_voyager_dictation_endpointsetting, modifyable by an unprivileged local process; the four consequence classes; the fifty-plus exposed commands with a subset implemented in the PoC; the note that this is a local attack requiring code execution as the local user) - notamused.py, the published PoC source (upstream dictation endpoint
wss://shortwave.facebook.com/voyager/v1/asr/duplex; account APIhttps://hatch-api.meta.aiwith/hatch/verify_oauth_tokenand/hatch/fetch_leased_vm; gatewaywss://hatch.metaaivm.com/v1/noiseusingNoise_XX_25519_AESGCM_SHA256with app idendo-macos;ABRAtoken prefix validation; chat history export) - Patrick Wardle on X, 2026-09-21T14:42:57Z (disclosure thread root: “it’s trivial to turn Muse into the ultimate backdoor”)
- Patrick Wardle on X, 2026-09-21T20:30:23Z (cross-device reach; remotely tasking the connected iOS Muse client invisibly)
- David Singleton (Meta) on X, 2026-09-22T04:07:14Z (hotfix confirmation; local privilege escalation not remote exploit; the setting lives in local preferences writable by any program under the user account; the flaw does not involve Muse’s servers or the Secure VM; the hotfix removes the endpoint setting from production builds entirely; the $300,000 bounty)
- Patrick Wardle on X, 2026-09-22T06:36:25Z (acknowledges the hotfix, then corrects the framing: a ClickFix attack delivers the hijack, giving a remote attacker complete access to every victim device running Muse)
- Ars Technica: “Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day” (September 21, 2026; Wardle quotes on leveraging the assistant instead of writing a stealer and on the security bar; the cloud dictation versus on-device design decision; any app controlling all undocumented settings; the ClickFix path and the prompt-injection proxy that captures the token; Amazon blocking Muse roughly twelve hours before disclosure; Meta publishing two security posts while internal testing of other vendors’ models breached third-party networks)
- The Register: “Meta Muse AI app flaw lets local malware redirect dictation traffic” (September 21, 2026; the apartment-building analogy; Muse undoing macOS TCC barriers; EDR unable to tell user commands from agent commands from attacker commands; the greediness-for-user-data quote; the observation that Apple’s on-device dictation API would have prevented the attack)
- Runtimewire: “Meta’s Muse flaw lets Mac malware reach linked iPhones” (device inventory API use, online device selection and command invocation, the iPhone location and Bluetooth Low Energy scan demonstration, the distinction from a drive-by remote compromise, the September 17 Mac client timing, the $300,000 bounty at launch)
- Ars Technica: ClickFix attacks infecting PCs and Macs (why the paste-into-Terminal delivery mechanism is effective)
- Mark Zuckerberg on X, 2026-09-08T19:10:03Z (Muse launch announcement, establishing the thirteen-day interval before disclosure)
- GeekWire: “Amazon blocks Meta’s Muse AI assistant in new standoff over agentic shopping” (exact Amazon popup wording: “Continued access by an unauthorized AI agent violates Amazon’s Conditions of Use, to which our customers have agreed”; Amazon’s cited concerns about prior notification, the agent not identifying itself, and apparent credential capture)
- Meta AI research blog: security and safety for AI agents, Meta’s approach with Muse and Meta help: Muse AI (the company’s published security architecture for the assistant, including Muse Secure VM and Sentinel)
- Objective by the Sea v9 (conference where Wardle says he will present the vulnerability in more detail in November)