⌁AI·CYBER·BRIEF▌
Vulnerabilities8 min read

Meta patched the Muse Mac zero-day in a day — but there is no version number to check

Meta removed the undocumented dictation setting on September 22, 2026, a day after Patrick Wardle published a proof of concept. No CVE, no fixed build number — here is how to check.

On September 21, 2026, Mac security researcher Patrick Wardle published proof-of-concept code showing that any program already running on a Mac under the logged-in user's own account could silently redirect the dictation traffic of Meta's Muse assistant to a server the attacker controls. Meta removed the setting that made this possible within roughly a day, and Wardle publicly confirmed the fix on September 22, 2026. If Muse is installed on a Mac you are responsible for, update the app and relaunch it — and note that Meta published no CVE identifier and no fixed build number, so "we updated" is the only assurance available.

What happened, in plain English

Muse is Meta's personal AI agent — an assistant that does not just answer questions but acts on your behalf, reading files, handling mail, managing your calendar. It launched on mobile and the web earlier in September 2026 and climbed to the top of the US App Store charts. A macOS app followed on September 17, 2026, able to work inside your files, messages, calendar, notes and mail.

One way you talk to Muse on a Mac is dictation: you speak, and the app sends your audio away to be transcribed. Wardle found that the address the app sends that audio to was stored in an ordinary, undocumented application setting named endo_voyager_dictation_endpoint, and that this setting could be changed by any process running as the logged-in user — no administrator password, no system permission prompt, no elevated privileges of any kind. Change the value and the microphone still works exactly as before. The user notices nothing. The audio simply goes somewhere else.

An analogy: a company keeps its records in a guarded vault with strict sign-in procedures, but the intercom on every desk has a small unlabelled dial on the back that decides which switchboard the call is routed through. Nothing about the vault is broken. Someone just turned the dial.

Two terms worth defining. A zero-day is a flaw made public before the vendor has a fix available — which is what this was, for about twenty-four hours. Prompt injection is smuggling instructions into the text or audio an AI agent processes, so the agent carries them out as though its owner had asked. Sitting in the dictation channel gave an attacker both halves: hear what you said, and change what the agent hears. Wardle's write-up notes it also allowed theft of the credentials the Muse client presents.

Are you affected? What to do now

You are in scope if Muse for macOS was installed on a machine you are responsible for between September 17 and September 22, 2026. Using Muse on iPhone or the web does not put you in scope — the flawed setting was in the Mac client. It was also not remotely exploitable: an attacker had to already be running code on that Mac as that user, through ordinary malware or a trojanised app. That precondition is what kept this from being an emergency.

Checklist, in order:

  • Find out whether Muse for Mac is installed anywhere. It is offered from Meta's own download page rather than the Mac App Store, so App Store inventories will not catch it. Check your MDM or endpoint agent's software inventory for the Muse application bundle.
  • Update the app and relaunch it. Meta's fix removed the undocumented setting from production builds. Quitting and reopening matters — a process already running keeps the code it started with.
  • Do not try to verify by version number. Meta published no advisory, CVE or fixed build number, so there is nothing to compare against. If you need an auditable record, request the build number from Meta; today the honest internal note is "updated on ", not "patched to version X".
  • If a Mac that ran Muse in that window shows any sign of compromise, treat it as credential exposure: sign out of Muse there, revoke and re-issue any API keys or connectors linked to the account, rotate credentials for the connected services, and review their audit logs for agent activity you cannot account for.
  • Review what you granted Muse — files, messages, calendar, notes, mail — and revoke anything it does not need. Access is opt-in per category. While you are there, decide a policy for unmanaged AI agents on managed Macs; that is the generic control that would have covered this one.
  • Do not go hunting for indicators of compromise. No vendor, CERT or researcher has published IOCs, a CVE identifier or a CVSS score, and there is no public evidence of exploitation in the wild. There is nothing official to search your logs for.

For most readers the honest summary is short: if nobody in your organisation installed Meta's Mac app in that five-day window, you have nothing to do today.

The expert view

The root cause is unremarkable, and that is the point. A security-relevant configuration value — the destination of an audio stream, and with it the agent's input channel — was stored somewhere writable by unprivileged same-user code, with no integrity check and no validation before use. Pinning the endpoint in the signed binary, or checking it against an allowlist, would have removed the issue entirely. It has the shape of an internal testing affordance that shipped to production.

The chain, conceptually: local code execution as the user, a change to that value, and from that moment the attacker occupies the dictation path — able to listen, to substitute instructions, and to take the credentials the client presents.

What makes this interesting is where it sits relative to Meta's own defences. On September 8, 2026, Meta published a security write-up for Muse describing a genuinely serious design: a dedicated cloud Linux VM per user, the agent isolated in a systemd-nspawn runtime cell, and an authorisation service called Sentinel as the sole permission authority — "Muse proposes actions, but only Sentinel can grant permission to perform action." The model never holds real credentials; it sees surrogate tokens that Sentinel swaps for the real ones at the network boundary. Classifiers watch for prompt injection, and the bug bounty awards "up to $300,000 for valid reports, including up to $130,000 for successful prompt injection attempts that affect one user."

Nearly all of that assumes the model is the component that might be turned against the user. This flaw sat a layer beneath it, in the local client that authenticates into the whole apparatus: Sentinel can gate every action faithfully and still be obedient to instructions substituted before they ever reached the cloud. It is the confused-deputy problem, restated for a deputy with a calendar, a mailbox and a set of connectors. Wardle's framing is access amplification — malware targets the agent to inherit its reach. The Hacker News reported on September 22, 2026 that he used a stolen Muse session token to make the assistant on his linked iPhone report its location, run a Bluetooth scan and list smart-home commands; Meta has not confirmed that demonstration.

On severity, David Singleton of Meta Superintelligence Labs told The Register the practical risk was "quite low", describing the issue as "a local privilege escalation, not a remote exploit". That is defensible on the access vector and understated on blast radius: the population that installs a two-week-old consumer AI agent and grants it mail, calendar and device linking is not a population with hardened endpoints. No CVSS vector was published, and readers should resist inventing one.

The response deserves credit stated plainly — roughly twenty-four hours from a public proof of concept to a shipped fix, confirmed by the researcher, is a good outcome.

The gap that remains is administrative rather than technical, and it is the part IT teams will feel. With no advisory, no CVE and no build number, a security team cannot evidence that a fleet is patched. VentureBeat reported on September 22, 2026 that Muse's available documentation shows no SIEM audit export, no IT admin console and no DLP integration, leaving enterprises without a central view of what the agent can reach; visibility has to be reconstructed from API-key issuance logs, connector activity and each connected service's own audit trail.

Still unknown: whether Meta was notified before publication and how long it had; whether Muse's other clients store comparable values the same way; and whether anything else undocumented shipped alongside this. Meta did not respond to VentureBeat's request for comment by publication time.

Official sources

Get the daily brief

AI + security signal by email: headlines, a two-line summary, a link. No noise, no spam.

How often