Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Meta Muse Security Flaw Lets Mac Malware Hijack AI Agent and Voice Traffic

Meta Muse Security Flaw Lets Mac Malware Hijack AI Agent and Voice Traffic

By:
Last updated:September 22, 2026
Human Written
  • Research code shows that local malware can redirect Muse’s voice traffic on Mac.

  • The flaw can expose prompts and a Muse login token. It can then let an attacker steer the agent.

  • Former Meta AI security manager Brian Wayman says he would not use Muse, citing security and privacy concerns.

Mac Flaw Lets Malware Redirect Meta’s Muse AI Voice Traffic, Researcher Finds

Meta’s new Muse AI agent is facing a security test less than two weeks after its launch. Security researcher Patrick Wardle has released code for a Mac zero-day called “not-a-mused.” It shows how a local process can change a hidden Muse setting. That can redirect voice prompts to a server run by an attacker.

The security flaw does not allow a hacker to break into a clean Mac device. The hacker must have the ability to execute a program as a local user.

Muse is made for the purpose of acting on behalf of the user. It can browse websites, fill out forms, and even handle email and make purchases. Also, it can work with linked services.

That broad access makes the local flaw more important. If malware can take control of Muse, it may be able to use access rights the user already gave the assistant.

Former Meta Manager Raises Concerns

The release has also drawn a strong reaction from Brian Wayman, who left Meta after working on its AI Security team. In a LinkedIn post shared alongside discussions about the flaw, Wayman said that he would never use Muse for himself due to security and privacy concerns.

Wayman’s LinkedIn profile describes him as a former Apple employee with 21 years of experience at Apple. The screenshot also identifies his recent Meta role as an Engineering Manager focused on AI Security.

His comments do not establish whether Meta knew about Wardle’s research before the public release. They do show that a former member of the company’s AI security organization has raised personal concerns about the product.

How the Muse Flaw Works

Wardle’s GitHub project identifies a hidden setting called endo_voyager_dictation_endpoint. A local process can change the setting without extra rights. The setting tells Muse where to send voice input for processing. By changing it, malware can point Muse toward a server run by an attacker.

The attack then waits for the user to use Muse’s microphone. The voice prompt can flow through the attacker’s server instead of the intended endpoint.

Wardle says this can create several problems. An attacker may read voice input or prompts. They may also add bad instructions into Muse. The research code can also capture a login token tied to the Muse session. That last part matters.

The attacker does not need to build a separate tool for every service Muse can access. Muse may already have the access needed to perform those tasks. The GitHub project sums up the risk this way: “Muse’s access can potentially become the attacker’s access.”

The Flaw can Extend Beyond the Mac

Wardle has also shown that a taken-over Muse session can interact with connected devices. Reports on the research say testing included a linked iPhone. The session could request information such as the phone’s location. It could also perform Bluetooth scans.

The security risks around iPhones also extend to scams that target users after their devices are stolen, including fake Apple Support calls.

Still, the local access requirement matters. This is not a remote attack that can compromise any Mac running Muse. An intruder must have the ability to execute a program on the machine first. That could come from malware. It could come from a bad download. It could also come from another compromise.

Once that foothold exists, the Muse flaw can make the attacker’s access much more powerful. The Register described the issue as an access-amplification risk because Muse may have far more permissions than normal local malware.

A Security Problem for an Agent with Broad Access

Meta’s own security design helps explain why the finding matters. The company says Muse runs inside a separate cloud system. It uses Sentinel to approve sensitive actions. Meta also says login data is stored separately from the agent.

Those safeguards are meant to limit damage when Muse reads bad content. Wardle’s finding instead targets the local app that helps a Mac user interact with the agent.

Meta has promoted Muse as a personal AI agent built with security safeguards. The company says Muse uses an isolated cloud computer. It says login data is protected. It also says a separate Sentinel layer handles sensitive actions. Meta also says users can set access rights. They can review important actions. They can do this before those actions happen.

Wardle argues that the design weakens some protections Mac normally provides. He points to Apple’s built-in permission safeguards. Wardle says AI apps can become one weak link when users give them wide access.

He also noted that Mac supports on-device voice input. In his view, using local voice-to-text work could have avoided this attack path.

What Users Should Know Now?

Wardle’s public repository provides working proof-of-concept code. So the issue is no longer only theoretical. Nonetheless, there’s publicly available evidence that this vulnerability has been exploited in real attacks.

At the time of publishing, Meta hasn’t released any fix for this vulnerability. Also, the tech company has not answered media requests for comment. That is the bigger security question raised by the release.

AI agents can be useful. Users give them access to files, accounts, devices, and services. The same access can also make a small local flaw far more valuable to an attacker.

Update: Reports suggest that Meta has patched the reported zero-day with a hotfix.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.