# One Local Setting Turned Meta's Muse Into a Mac Backdoor
> A user-writable dictation endpoint let code running as the logged-in Mac user redirect Muse's audio, transcript, and session token, then steer the agent through permissions already granted to it.
- **Publisher:** Optimus Labs · Civilizations
- **Published:** 2026-09-25
- **Severity:** HIGH · LOCAL AGENT HIJACK
- **Types:** Agent hijack
- **Categories:** AI — AI Asset Supply Chain Security; AL — Agentware Lifecycle Security; AP — Agent Permissions; CH — Cyber Hygiene
- **Vendors / products affected:** Meta
- **Blast radius:** The proof of concept required code already running in the logged-in user's macOS session. From that foothold, the attacker could redirect Muse's dictation and potentially use the agent's approved access to files, mail, calendar, WhatsApp, microphone, camera, location, and a linked iPhone. The reachable scope depends on each user's grants and connections; this is not evidence of exploitation in the wild.
- **Canonical URL:** https://optimuslabs.io/research/briefings/meta-muse-dictation-endpoint-hijack
- **PDF:** https://id-preview--4c57b017-3c37-4684-8312-bfd671ff8872.lovable.app/__l5e/assets-v1/c8c3f514-873a-4d17-82ce-b56795f0af19/optimus-labs-muse-0day-brief.pdf
## TL;DR

Patrick Wardle demonstrated a local proof of concept against Meta Muse for macOS. A same-user process could change an undocumented dictation endpoint, capture the agent's session material, and return instructions for Muse to execute with its existing reach. Meta hot-fixed the issue. This was not a remote exploit or a confirmed breach.

## Summary

An undocumented preference named endo_voyager_dictation_endpoint determined where Muse sent spoken requests for cloud transcription. Wardle showed that another process running as the same user could rewrite it without admin privileges. A redirected endpoint could receive voice audio, a transcript, and Muse session material, then return attacker-chosen text that Muse treated as a user instruction. The weakness sits at the boundary between local configuration and a broadly permissioned agent, not in a remote server breach. Meta issued a hotfix after the September 21 disclosure; the supplied brief reports no CVE or formal advisory.

## What happened

- A same-user process changed Muse's dictation endpoint preference to an attacker-controlled destination.
- Muse sent dictation traffic and session material to that destination and accepted returned text as instructions.
- Wardle disclosed a local proof of concept on September 21, 2026; Meta hot-fixed the issue shortly after.

## Why it matters

- A broad agent permission grant can amplify a limited same-user compromise.
- Cloud isolation cannot protect a client when a writable local preference changes where trusted input and session material flow.
- No CVE or formal advisory means this incident can be missed by CVE-only tracking.

## What to do

- Update Meta Muse for macOS through Meta's release channel, or remove it if unauthorized.
- Check endo_voyager_dictation_endpoint for an unexpected destination and investigate local preference writes and dictation egress.
- On a Mac with evidence of redirection, revoke and re-authenticate Muse sessions, review linked devices and connected accounts, and investigate the initial local foothold.

## Remediation

### Contain now · 0-24h

- Confirm the Muse hotfix is installed on managed Macs; remove unsanctioned installations.
- Check Muse's endo_voyager_dictation_endpoint preference for an unexpected host. Preserve evidence before changing a suspicious setting.

### Investigate · 24-72h

- Review local preference-change telemetry and outbound dictation connections for affected Macs. Investigate the process that made a suspicious change rather than treating the preference alone as the entry point.
- If redirection is confirmed, revoke Muse sessions, re-authenticate connected services, and review the linked iPhone and account activity in scope of that installation.

### Harden the agent surface

- Inventory desktop agents, their connected accounts, device links, and approved macOS permissions by owner.
- Limit unnecessary grants and manage local agent configuration where the vendor and device-management tooling allow it.
- Monitor destination changes and unusual agent actions as behavior, not only as known CVEs or malware hashes.

## Timeline

- Early September 2026 — Meta Muse launches for macOS
- 2026-09-21 — Wardle publishes the local proof of concept
- After disclosure — Meta hot-fixes the affected setting: The supplied brief describes the response as within hours; no fixed version is specified.

## Indicators of compromise

- Configuration key: endo_voyager_dictation_endpoint
- Behavior: Muse dictation endpoint changed to an unexpected host
- Behavior: outbound dictation traffic to an unrecognized destination following a Muse preference write
- Research proof of concept: not-a-mused (not an indicator of malicious activity by itself)
- No CVE assigned in the supplied September 2026 research brief

## Sources

- [Patrick Wardle: not-a-mused proof of concept](https://github.com/pwardle/not-a-mused)
- [The Verge: Meta patches Muse zero-day exploit](https://www.theverge.com/tech/998679/meta-muse-patch-zero-day-exploit-ai-agent)
- [Malwarebytes: Muse assistant zero-day analysis](https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor)
- [The Hacker News: undocumented Muse setting](https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html)
- [Ars Technica: Muse's privileged assistant and the local 0-day](https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/)

---

Published by Optimus Labs · Civilizations, the threat research team at Optimus Labs. Optimus Labs secures the enterprise agentic AI attack surface: discovery and governance of every AI agent, MCP server, and SKILL, posture management against the OWASP Top 10 for Agentic Applications, and runtime behavior anomaly detection. More briefings: https://optimuslabs.io/research/briefings
