{
  "@context": "https://schema.org",
  "@type": "Report",
  "url": "https://optimuslabs.io/research/briefings/meta-muse-dictation-endpoint-hijack",
  "identifier": "meta-muse-dictation-endpoint-hijack",
  "headline": "One Local Setting Turned Meta's Muse Into a Mac Backdoor",
  "name": "One Local Setting Turned Meta's Muse Into a Mac Backdoor",
  "abstract": "A user-writable dictation endpoint let code running as the logged-in Mac user redirect Muse's audio, transcript, and session token, then steer the agent through permissions already granted to it.",
  "description": "An undocumented preference named endo_voyager_dictation_endpoint determined where Muse sent spoken requests for cloud transcription. Wardle showed that another process running as the same user could rewrite it without admin privileges. A redirected endpoint could receive voice audio, a transcript, and Muse session material, then return attacker-chosen text that Muse treated as a user instruction. The weakness sits at the boundary between local configuration and a broadly permissioned agent, not in a remote server breach. Meta issued a hotfix after the September 21 disclosure; the supplied brief reports no CVE or formal advisory.",
  "datePublished": "2026-09-25",
  "dateModified": "2026-09-25",
  "inLanguage": "en",
  "isAccessibleForFree": true,
  "author": {
    "@type": "Organization",
    "name": "Optimus Labs · Civilizations",
    "url": "https://optimuslabs.io/research/briefings"
  },
  "publisher": {
    "@type": "Organization",
    "name": "Optimus Labs",
    "url": "https://optimuslabs.io"
  },
  "keywords": [
    "Meta",
    "Agent hijack",
    "AI Asset Supply Chain Security",
    "Agentware Lifecycle Security",
    "Agent Permissions",
    "Cyber Hygiene",
    "agentic AI security",
    "AI agent supply chain"
  ],
  "about": [
    {
      "@type": "Thing",
      "name": "Meta"
    }
  ],
  "citation": [
    {
      "@type": "CreativeWork",
      "name": "Patrick Wardle: not-a-mused proof of concept",
      "url": "https://github.com/pwardle/not-a-mused"
    },
    {
      "@type": "CreativeWork",
      "name": "The Verge: Meta patches Muse zero-day exploit",
      "url": "https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent"
    },
    {
      "@type": "CreativeWork",
      "name": "Malwarebytes: Muse assistant zero-day analysis",
      "url": "https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor"
    },
    {
      "@type": "CreativeWork",
      "name": "The Hacker News: undocumented Muse setting",
      "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
    },
    {
      "@type": "CreativeWork",
      "name": "Ars Technica: Muse's privileged assistant and the local 0-day",
      "url": "https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/"
    }
  ],
  "encoding": [
    {
      "@type": "MediaObject",
      "encodingFormat": "text/markdown",
      "contentUrl": "https://optimuslabs.io/research/briefings/meta-muse-dictation-endpoint-hijack.md"
    },
    {
      "@type": "MediaObject",
      "encodingFormat": "application/json",
      "contentUrl": "https://optimuslabs.io/research/briefings/meta-muse-dictation-endpoint-hijack.json"
    }
  ],
  "additionalProperty": [
    {
      "@type": "PropertyValue",
      "name": "severity",
      "value": "HIGH · LOCAL AGENT HIJACK"
    },
    {
      "@type": "PropertyValue",
      "name": "blastRadius",
      "value": "The proof of concept required code already running in the logged-in user's macOS session. From that foothold, the attacker could redirect Muse's dictation and potentially use the agent's approved access to files, mail, calendar, WhatsApp, microphone, camera, location, and a linked iPhone. The reachable scope depends on each user's grants and connections; this is not evidence of exploitation in the wild."
    }
  ],
  "briefing": {
    "slug": "meta-muse-dictation-endpoint-hijack",
    "number": 12,
    "title": "One Local Setting Turned Meta's Muse Into a Mac Backdoor",
    "dek": "A user-writable dictation endpoint let code running as the logged-in Mac user redirect Muse's audio, transcript, and session token, then steer the agent through permissions already granted to it.",
    "tldr": "Patrick Wardle demonstrated a local proof of concept against Meta Muse for macOS. A same-user process could change an undocumented dictation endpoint, capture the agent's session material, and return instructions for Muse to execute with its existing reach. Meta hot-fixed the issue. This was not a remote exploit or a confirmed breach.",
    "date": "2026-09-25",
    "severity": "high",
    "severityLabel": "HIGH · LOCAL AGENT HIJACK",
    "types": [
      "agent-hijack"
    ],
    "categories": [
      "AI",
      "AL",
      "AP",
      "CH"
    ],
    "vendors": [
      "Meta"
    ],
    "featured": true,
    "blastRadius": "The proof of concept required code already running in the logged-in user's macOS session. From that foothold, the attacker could redirect Muse's dictation and potentially use the agent's approved access to files, mail, calendar, WhatsApp, microphone, camera, location, and a linked iPhone. The reachable scope depends on each user's grants and connections; this is not evidence of exploitation in the wild.",
    "summary": "An undocumented preference named endo_voyager_dictation_endpoint determined where Muse sent spoken requests for cloud transcription. Wardle showed that another process running as the same user could rewrite it without admin privileges. A redirected endpoint could receive voice audio, a transcript, and Muse session material, then return attacker-chosen text that Muse treated as a user instruction. The weakness sits at the boundary between local configuration and a broadly permissioned agent, not in a remote server breach. Meta issued a hotfix after the September 21 disclosure; the supplied brief reports no CVE or formal advisory.",
    "affected": {
      "checks": [
        "Was Meta Muse for macOS installed before the September 2026 hotfix?",
        "Could untrusted code run in the same logged-in user's session, including through a malicious download or social-engineering lure?",
        "Was Muse's dictation endpoint preference changed to a host you do not recognize?",
        "Which device, account, and macOS permissions did the affected Muse installation hold?"
      ],
      "notAffected": [
        "This proof of concept does not establish a remote, unauthenticated entry point into an otherwise clean Mac.",
        "A fully updated Muse install with no suspicious preference changes is outside the demonstrated pre-hotfix path."
      ],
      "note": "The source documents do not identify a safe version number. Confirm the update through Meta's current release channel."
    },
    "narrativeSections": [
      {
        "heading": "The local foothold came first",
        "paragraphs": [
          "The attack starts with a process already running as the Mac user. Wardle's not-a-mused proof of concept did not remotely break into Muse or require an administrator prompt. A ClickFix-style lure or local malware is a plausible entry path, not a reported delivery campaign in this case.",
          "That process rewrites endo_voyager_dictation_endpoint, an undocumented Muse preference controlling the cloud dictation destination. The attacker-controlled address in the diagram is illustrative, not a live indicator."
        ]
      },
      {
        "heading": "The agent crossed the trust boundary",
        "paragraphs": [
          "When the user spoke to Muse, the redirected endpoint could receive the audio, transcription data, and session material. The attacker could return text for the agent to interpret as the user's request, rather than gaining each macOS permission individually.",
          "The permission set is the multiplier: files, microphone, camera, location, connected accounts, and a linked iPhone were in scope of the demonstrated agent capabilities. Actual access depends on what the user had approved and connected."
        ]
      },
      {
        "heading": "What the demonstration does and does not prove",
        "paragraphs": [
          "The researcher demonstrated a working attack path against a privileged client. The supplied reporting does not establish a customer breach, an in-the-wild campaign, or a remote zero-click compromise. Meta described the practical risk as low because same-user code must be present and issued a hotfix.",
          "The lasting lesson is narrower and more useful than 'the cloud failed': a local setting can redirect an agent that already has trusted access. Inventorying installed agents and their grants matters alongside cloud isolation and connector controls."
        ]
      }
    ],
    "whatHappened": [
      "A same-user process changed Muse's dictation endpoint preference to an attacker-controlled destination.",
      "Muse sent dictation traffic and session material to that destination and accepted returned text as instructions.",
      "Wardle disclosed a local proof of concept on September 21, 2026; Meta hot-fixed the issue shortly after."
    ],
    "whyItMatters": [
      "A broad agent permission grant can amplify a limited same-user compromise.",
      "Cloud isolation cannot protect a client when a writable local preference changes where trusted input and session material flow.",
      "No CVE or formal advisory means this incident can be missed by CVE-only tracking."
    ],
    "whatToDo": [
      "Update Meta Muse for macOS through Meta's release channel, or remove it if unauthorized.",
      "Check endo_voyager_dictation_endpoint for an unexpected destination and investigate local preference writes and dictation egress.",
      "On a Mac with evidence of redirection, revoke and re-authenticate Muse sessions, review linked devices and connected accounts, and investigate the initial local foothold."
    ],
    "remediation": [
      {
        "window": "Contain now · 0-24h",
        "actions": [
          "Confirm the Muse hotfix is installed on managed Macs; remove unsanctioned installations.",
          "Check Muse's endo_voyager_dictation_endpoint preference for an unexpected host. Preserve evidence before changing a suspicious setting."
        ]
      },
      {
        "window": "Investigate · 24-72h",
        "actions": [
          "Review local preference-change telemetry and outbound dictation connections for affected Macs. Investigate the process that made a suspicious change rather than treating the preference alone as the entry point.",
          "If redirection is confirmed, revoke Muse sessions, re-authenticate connected services, and review the linked iPhone and account activity in scope of that installation."
        ]
      },
      {
        "window": "Harden the agent surface",
        "actions": [
          "Inventory desktop agents, their connected accounts, device links, and approved macOS permissions by owner.",
          "Limit unnecessary grants and manage local agent configuration where the vendor and device-management tooling allow it.",
          "Monitor destination changes and unusual agent actions as behavior, not only as known CVEs or malware hashes."
        ]
      }
    ],
    "indicators": [
      "Configuration key: endo_voyager_dictation_endpoint",
      "Behavior: Muse dictation endpoint changed to an unexpected host",
      "Behavior: outbound dictation traffic to an unrecognized destination following a Muse preference write",
      "Research proof of concept: not-a-mused (not an indicator of malicious activity by itself)",
      "No CVE assigned in the supplied September 2026 research brief"
    ],
    "sourcing": {
      "confirmed": [
        "Patrick Wardle's public not-a-mused proof of concept demonstrates the local same-user attack path; Meta's hotfix and its low-practical-risk characterization are covered by The Verge and the reporting linked below.",
        "The supplied Civilizations deck and one-page diagram describe the agent permissions and containment sequence. The diagram's attacker.tld address is illustrative."
      ],
      "assessed": [
        "The broader enterprise blast radius depends on each installation's granted permissions and connected services. It is not a measured victim count.",
        "No known in-the-wild use is reported by the supplied brief. Absence of a CVE is a tracking gap, not proof of exploitation."
      ]
    },
    "sources": [
      {
        "label": "Patrick Wardle: not-a-mused proof of concept",
        "url": "https://github.com/pwardle/not-a-mused"
      },
      {
        "label": "The Verge: Meta patches Muse zero-day exploit",
        "url": "https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent"
      },
      {
        "label": "Malwarebytes: Muse assistant zero-day analysis",
        "url": "https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor"
      },
      {
        "label": "The Hacker News: undocumented Muse setting",
        "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
      },
      {
        "label": "Ars Technica: Muse's privileged assistant and the local 0-day",
        "url": "https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/"
      }
    ],
    "image": "https://id-preview--4c57b017-3c37-4684-8312-bfd671ff8872.lovable.app/__l5e/assets-v1/bcad595c-9793-4813-b8ee-072f300f859b/muse-0day-trust-boundaries.png",
    "imageAlt": "Muse local trust-boundary diagram: same-user malware rewrites the dictation endpoint, sends voice and session material to an attacker-controlled server, and returns instructions to Muse, which can act with its already granted permissions. The illustrated attacker.tld address is an example, not an IOC.",
    "pdfUrl": "https://id-preview--4c57b017-3c37-4684-8312-bfd671ff8872.lovable.app/__l5e/assets-v1/c8c3f514-873a-4d17-82ce-b56795f0af19/optimus-labs-muse-0day-brief.pdf",
    "timeline": [
      {
        "date": "Early September 2026",
        "label": "Meta Muse launches for macOS"
      },
      {
        "date": "2026-09-21",
        "label": "Wardle publishes the local proof of concept"
      },
      {
        "date": "After disclosure",
        "label": "Meta hot-fixes the affected setting",
        "note": "The supplied brief describes the response as within hours; no fixed version is specified."
      }
    ]
  }
}