Menu Close

Meta patches Muse macOS zero-day that hijacked dictation endpoint

Editorial security board: macOS Muse agent privilege panel with DICTATION ENDPOINT HIJACK, LOCAL PRIVILEGE ESCALATION, and HOTFIX ISSUED chips plus Meta mark and ClickFix cue; no likenesses, not shopping-barrier or Muse Mac twin.

Meta has issued a hotfix for a macOS Muse zero-day that could let local malware redirect the agent’s cloud dictation traffic and capture its authentication token, closing the hole hours after public disclosure. The patch follows a same-day cycle that started with a researcher write-up and ended with Meta framing the bug as local privilege escalation rather than a remote break-in.

On the evening of September 21, Ars Technica (Dan Goodin) reported that researcher Patrick Wardle found the flaw: any local app or terminal session could change an undocumented setting, endo_voyager_dictation_endpoint, and point Muse’s cloud dictation at an attacker-controlled endpoint. From there, an attacker could capture the Muse auth token and leverage the agent’s privileges — including access paths tied to files, the camera, and other user-granted capabilities. Wardle noted ClickFix-style lures can deliver the initial local foothold. Meta did not answer Ars Technica’s questions at disclosure. Because Muse already runs with broad user-granted privileges on the Mac, a redirected dictation path that yields the agent’s auth token is enough to put those privileges in play without needing a separate remote exploit.

On September 22, The Verge (Jess Weatherbed, 11:53 UTC) reported that Meta shipped a hotfix hours after the Ars report. David Singleton of Meta Superintelligence Labs said on X that the issue was local privilege escalation, not a remote attack, and that practical risk was low because malicious code must already be running under the user’s account — while confirming Meta still issued the hotfix. That framing matches the disclosure mechanics: the setting change and token capture require code already executing as the signed-in user, which lowers remote blast radius even as it keeps the local agent surface worth patching quickly.

The episode lands while Muse is already under retail pressure: Amazon recently blocked Muse from shopping on Amazon.com. Together, the shopping dispute and the macOS dictation-endpoint bug underline the same operating reality for privileged AI agents: they inherit every permission the user grants, and every local bug that can steer those permissions.

The Hacker News also covered the undocumented setting and the local redirect path after the Ars disclosure.

Sources

0 0 votes
Article Rating
Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x