Security researcher Patrick Wardle of the Objective-See Foundation has uncovered a severe security vulnerability in the Mac application of the AI service Meta Muse. The flaw allows attackers to redirect application traffic and siphon off sensitive information. Wardle considers the associated risk so severe that he warns against installing the current macOS version.
Data Redirection via Undocumented Settings
The root cause of the issue lies in an undocumented configuration variable named endo_voyager_dictation_endpoint. According to Wardle, any local process on the Mac can modify this setting without administrative privileges. If malware on the system manages to do so, the application’s dictation traffic is redirected to an attacker-controlled server.
While the attack requires local malware to already be running on the machine, the trigger occurs invisibly: As soon as a user accesses the microphone feature for a spoken prompt, the app transmits the data stream along with authentication tokens to the manipulated endpoint. With these tokens, a full takeover of the Muse account is possible, granting unauthorized parties access to personal data and allowing them to impersonate the user. Wardle noted that Meta could have prevented this attack vector by relying on Apple’s official on-device dictation API. As part of a proof-of-concept demonstration dubbed “not-a-mused,” the researcher also demonstrated how the app could be used to locate an iPhone and initiate a Bluetooth scan.
High Download Numbers Despite Growing Criticism
The security warning comes amid a rapidly growing user base. Meta launched the service on September 8, 2026, followed by the Mac client on September 17, 2026. According to figures from analytics firm Sensor Tower, the more than 2.5 million downloads within the first 13 days applied to the mobile app (approximately 1.5 million on iOS and around 1.1 million on Android), not the Mac client. Soon after its launch, the system revealed ambitious goals: While Meta Muse is designed as a personal AI agent to handle routine tasks, e-commerce giants are already drawing boundaries. Amazon, for instance, blocked the service from making purchases on its marketplace, arguing that Meta had not obtained permission and was storing order histories and customer data.
Additionally, the program’s data collection practices have drawn scrutiny: By default, user data feeds into model training unless users jump through hoops to opt out.
Recommendations for Users
Although Meta operates a bug bounty program offering payouts of up to $300,000, the company has not yet issued a statement regarding the reported zero-day flaw. No official CVE identifier has been assigned at this time.
Affected Mac users should avoid the application’s dictation feature until a security update is released, or uninstall the software entirely for the time being to prevent the leakage of session tokens.
Sources: Borncity.com















