Meta says it issued a hotfix for its Muse Mac app on September 22 after security researcher Patrick Wardle demonstrated that a local process could redirect the agent’s dictation traffic to an attacker-controlled endpoint. The report matters because Muse is not a plain chatbot: it is designed to act across apps and accounts, so a weakness in how the Mac client handles input can become a path to token theft and misuse of the agent’s permissions. The reporting here comes from The Register and 9to5Mac, alongside Meta’s earlier launch post on Muse security.
What was confirmed
According to The Register, Wardle published a proof of concept called not-a-mused on September 21 showing that an unprivileged local process on macOS could change an undocumented Muse setting, endo_voyager_dictation_endpoint, and redirect dictated prompts away from Meta’s servers. Once that traffic is diverted, the attacker can potentially capture the Muse authentication token tied to the session and use it to operate the agent.
9to5Mac reported additional proof-of-concept abuse: Wardle showed that a hijacked Muse account could be used to write files to the Mac, take photos with the camera, and retrieve the location of a linked iPhone. Those examples illustrate the post-compromise blast radius, but they do not change the core limit of the attack: the attacker first needs code running locally on the user’s machine.
How the flaw bypassed the safety story
Meta’s own security write-up for Muse, published on research.meta.ai, describes a different layer of defense. The company says Muse runs inside a dedicated cloud VM, routes sensitive actions through a Sentinel approval system, and tries to keep real credentials out of the model’s reach. Meta says that architecture is designed to reduce damage from prompt injection and other model-level attacks.
Wardle’s finding points to a weaker boundary: the macOS client. If a local process can rewrite where dictation is sent, the agent’s cloud isolation no longer protects the first hop. In practical terms, the bug creates an opening for voice interception, prompt injection, and session abuse before Meta’s server-side controls can help. For AI agents that can send messages, fill forms, or make purchases, that is not a cosmetic defect. It is an attack surface that can convert local malware into control of a high-trust assistant.
The sources are careful on one important point: this was a local attack, not a direct remote exploit. An attacker still needs to execute code on the user’s Mac. That constraint makes the issue narrower than a wormable internet bug, but not trivial. As The Register notes, a social-engineering path such as a ClickFix-style trick can be enough to get a user to run a command in Terminal.
Why Meta’s response is meaningful, but incomplete
Meta had recently emphasized Muse’s security posture and opened a bug bounty program with awards of up to $300,000 for valid reports, including prompt-injection findings. The hotfix, which Meta says it issued on September 22, acknowledges a product flaw. The available sources do not establish the precise patched build or independently test its effectiveness.
At the same time, the fix does not erase the underlying lesson. The vulnerability existed in the client-side trust boundary, not in the model. That means the practical security question for AI agents is broader than whether the backend is isolated or whether credentials are hidden from the model. Client settings, local permissions, and how an app handles routing of sensitive inputs are part of the security model too.
Meta’s response, as reported by The Register after the story was filed, was that the company had revised the app and considered the issue a local privilege-escalation attack rather than a remote exploit. That framing narrows the immediate risk, but it does not remove the need for users and administrators to treat the macOS client as part of the trust chain.
The decision boundary for users and builders
For people using AI agents on desktop, the decision boundary is straightforward: a cloud-hardened agent is only as safe as its local client and input path. If an app can be made to send voice, prompts, or credentials somewhere else by a low-privilege process, then its agentic permissions can be turned against the user.
For product teams, the lesson is even sharper. If the agent can act on the user’s behalf, the input path should be treated as security-critical infrastructure, not just an interface detail. That means versioned endpoints, explicit permission checks, and a hard distinction between approved network destinations and editable local settings.
If you use Muse on Mac, install the latest available update, check Meta’s release information for the affected and fixed builds, and review the permissions and connected accounts you have granted the agent.