HomeSecurityMuse dictation: Critical local vulnerability in macOS

Muse dictation: Critical local vulnerability in macOS

A vulnerability in Muse, Meta's new AI personal assistant, affects the Muse dictation and allows an application or command running locally on a Mac to gain broad control of the agent. The disclosure is a local zero-day and not a remote attack, but the access that Muse is requesting makes the finding particularly serious.

The issue was first reported by researcher Patrick Wardle, founder of Objective-See, who published a proof of concept called not-a-mused. The analysis was reported by Ars Technica and The Register, with no mention of a fix available from Meta so far.

See also: Meta Muse: The AI ​​assistant doesn't know how it works exactly

Muse dictation vulnerability macOS

Muse dictation: How the vulnerability works in Muse

According to Wardle's description, the application includes an undocumented setting called endo_voyager_dictation_endpoint. A process running on the same Mac could modify the setting without special privileges and redirect dictation traffic to a server controlled by the attacker.

The vulnerability in Muse already requires local code execution. It is not, based on the available evidence, a remotely launched attack against an unsuspecting computer. This limits the initial step, but does not eliminate the risk: a malicious program installed in another way could exploit Muse as an access amplifier.

The redirection can expose the audio of Muse dictation and the prompts sent to the backend model. The researcher also warns of potential identity theft, malicious instructions, and abuse of services the user has connected to. The finding is essentially described as a local privilege escalation.

This means that the attack does not need to directly bypass Meta's systems. It simply leverages a local presence and turns Muse into a bridge to accounts, files, or conversations that the user has already approved. The extent of the impact depends on the permissions of each installation, not a single default set of permissions.

Muse dictation redirection dictation

Why agent access increases risk

Muse is not just a conversational assistant. Meta designed it to connect to email, calendar, WhatsApp, and other apps, and can fill out forms, make appointments, and make purchases. Meta's official presentation says that the user chooses which services to connect and how much access to give.

The company has described the Muse Secure VM, Sentinel controller, and pre-sensitive action approvals as key safeguards. However, the vulnerability in Muse affects the local macOS program and the dictation path, before full privileges are exercised within the service. Meta has not publicly mentioned a specific release that fixes the issue.

Meta has not publicly announced a specific version of Muse dictation that fixes the issue, nor has a CVE identifier been published. The absence of official confirmation should not be taken as an indication that the finding is harmless; the details come from independent research, and the demo code shows a realistic local path.

See also: ClickFix attacks distribute new ChainScript RAT

Privacy risk from Muse

What users can do now

Until an official update is released for Muse dictation, the SecNews technical team recommends limiting Muse connections and permissions to what is absolutely necessary. Mac users should review access to microphone, camera, files, location, and calendar, disconnect services that are not needed, and consider temporarily disabling the application.

At the same time, attention should be paid to unknown programs and files that may give a malicious process local execution. Meta recognizes that agents are not immune to attacks and recommends minimal privileges, approval control, and constant monitoring of their actions.

Organizations testing agents on corporate Macs should treat the application like any software with access to critical data. Logging installations, restricting permissions, and promptly notifying users of new versions reduce the potential for abuse, but are not a substitute for an official patch.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Meta Muse: Amazon blocks AI shopping agent

Muse permissions check

The Muse and Muse dictation show that the security of an agent does not depend solely on its cloud environment. The more data and actions an application collects, the more important it becomes to protect the computer itself where it runs. The SecNews editorial team will monitor any announcement from Meta for a fix or revocation instructions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS