Skip to content
Meta Muse AI app flaw lets local malware redirect dictation traffic

Meta Muse AI app flaw lets local malware redirect dictation traffic

Theregister • September 21, 2026

Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 13 hours ago

Treasury chief says AI bosses, not their bots, will carry the can for criminal acts

Amazon shows Meta's Muse AI shopping agent the door 19 hours ago

Amazon shows Meta's Muse AI shopping agent the door

Clop gets a taste of its own medicine after ShinyHunters hijack leak site 19 hours ago

Clop gets a taste of its own medicine after ShinyHunters hijack leak site

Rustaceans warned of job interviews with a malicious payload 21 hours ago

Rustaceans warned of job interviews with a malicious payload

Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM.

"Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing prior expansive claims the privacy of its data gathering business .

But Meta's musing Muse appears to be a bit overstated: an attacker capable of executing local code may be able to gain more access than a Muse user might expect.

Security researcher Patrick Wardle, founder of nonprofit Objective-See , has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows an unprivileged local process to redirect Muse's dictation traffic and potentially abuse access granted to the app.

Muse, he explains in the project repo, has an undocumented setting called endo_voyager_dictation_endpoint that an attacker running code locally can modify without special privileges to redirect dictation traffic to an attacker-controlled endpoint, potentially exposing dictated audio and prompts sent to the backend AI model. The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse.

The vulnerability is not an issue for a remote attacker. It requires the ability to run local code. So the main concern, says Wardle, is that the vulnerability gives local malware far broader access than it would have otherwise. Essentially, it's a privilege escalation vulnerability.

In a phone interview with The Register , Wardle likened the situation to living in an apartment building. "Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments," he said.

Apple, said Wardle, has done a really good job with its Transparency, Consent, and Control (TCC) framework, which manages access to sensitive data on macOS, and with privilege separation. But his concern is that AI apps undo these barriers because they request or require so much access to data and tools.

Of AI apps, he said, "they're super convenient and super empowering. But they have so much access if you configure them to be useful. They basically could do anything on your computer."

As such, he said, they become potentially a single point of failure that breaks operating system security controls.

"You know these AI companies have really great AI models for finding bugs," said Wardle. "Are they not running them against [their own apps]? Is the priority not the security of their own apps?"

Wardle said that endpoint detection and response (EDR) software has gotten better on macOS largely because everything is code signed, so it's easy to identify processes that are not notarized and should not be allowed to run. But with AI agents given broad permissions and access, the EDR product can't tell whether commands are coming from the user, an agent, or an attacker.

These agents need access, said Wardle, in order to be useful to people. What's missing from the makers of AI apps, he said, is a sense of responsibility for the level of access their apps seek.

Wardle added that Apple provides on-device local dictation and if Meta chose to use that API, this vulnerability would not exist. Instead, he suggested, Meta chose not to use Apple's service, presumably because it wants access to that data.

"I think some of their greediness for user data kind of opens the door, makes a bigger attack surface," he said. "But at the end of the day, these AI companies, they're racing for what's . User privacy and security, those aren't priorities."

Meta did not immediately respond to a request for .®

GOV.UK founder warns AI gold rush could leave Britain locked in

Mike Bracken says the dash to adopt sovereign AI risks giving more control to a handful of tech suppliers

Alibaba Cloud plans six-year stroll to 20GW of datacenters, reveals chip to power them

USA alone has 37GW under construction, but Alibaba doesn't think the AI boom will run out of steam

HPE makes its “unified storage” claim real as B10000 R6 hits GA

PARTNER CONTENT: Pairs block and adjacent file workloads with independent scaling of performance and capacity

Gartner predicts 55 percent of enterprise VMware users will be investigating an exit by 2029

Chasing pack has its problems too, with maturity, cost, and complex licenses

Your cloud survived everything except the real world

War damage, air traffic chaos, and a storage shortage expose the cost of treating resilience as someone else's problem

California tightens datacenter rules on water and power

Public pushback puts bit barn resource use under the microscope

SAAS Salesforce staggers back to feet after global outage

Salesforce staggers back to feet after global outage

databases Oracle celebrates banner quarter with another round of layoffs

Oracle celebrates banner quarter with another round of layoffs

Anthropic decides to support OpenAI's markdown instructions spec

Anthropic decides to support OpenAI's markdown instructions spec

Microsoft agentically ports Copilot runtime to Rust for $120K

Microsoft agentically ports Copilot runtime to Rust for $120K

ai and ml Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent

Ex-FTC boss Khan urges Uncle Sam to break out the handcuffs for AI CEOs, citing 1934 precedent

software Fedora 45 beta drags the Linux console into the 21st century

Fedora 45 beta drags the Linux console into the 21st century

Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club Fueled by the AI boom, the House of Zen's rise isn't just Instinct - Lisa Su is riding high on some Epyc design chops too

Perpetual underdog AMD nips at Nvidia's heels as it joins the $1T club

Fueled by the AI boom, the House of Zen's rise isn't just Instinct - Lisa Su is riding high on some Epyc design chops too

Treasury chief says AI bosses, not their bots, will carry the can for criminal acts 'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face

Treasury chief says AI bosses, not their bots, will carry the can for criminal acts

'Humans are responsible, not the AI,' argues Scott Bessent as he calls out OpenAI agents' hack of Hugging Face

Google smacks forehead, realizes $899+ thin-and-lights were what it was missing 'A new category,' insists the Chocolate Factory, not a premium Chromebook - yet some of the family resemblance remains

Google smacks forehead, realizes $899+ thin-and-lights were what it was missing

'A new category,' insists the Chocolate Factory, not a premium Chromebook - yet some of the family resemblance remains

AI can't outprompt a shortage of power, water, and land Forrester predicts operators will face tariffs, grid commitments, and tougher community scrutiny

AI can't outprompt a shortage of power, water, and land

Forrester predicts operators will face tariffs, grid commitments, and tougher community scrutiny

Salesforce wants to charge for AI outcomes, but first it needs to figure out how Seats, Flex Credits, and all-you-can-eat contracts make for an 'anxiety-filled architecture'

Salesforce wants to charge for AI outcomes, but first it needs to figure out how

Seats, Flex Credits, and all-you-can-eat contracts make for an 'anxiety-filled architecture'

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot