Patrick Wardle's not-a-mused zero-day showed local malware could hijack Meta's Muse agent

On September 21, 2026, less than two weeks after Meta launched its Muse personal agent, macOS security researcher Patrick Wardle published a proof-of-concept exploit for a zero-day in the Muse Mac app, which he called “not-a-mused.” Muse exposes an undocumented setting, endo_voyager_dictation_endpoint, that any local process can change without special privileges. Once it points at an attacker’s server, the prompts a user dictates to Muse go there instead.

Wardle’s write-up lists what that buys an attacker: capture of dictated audio and prompts, prompt injection into Muse, theft of Muse authentication material, and abuse of whatever access the user has granted the agent. His proof of concept implements a subset of the more than 50 commands Muse exposes; the user only has to press the microphone button and speak to trigger it. His summary: “Muse’s access can potentially become the attacker’s access.” He is explicit that this is a local attack - the attacker must already be able to run code as the user.

The Register reported that after its story was filed, David Singleton of Meta Superintelligence Labs said Meta had issued a hotfix to the app, while describing the practical risk as quite low because local code execution is a prerequisite.

Why it matters: the bug itself is mundane - a hidden configuration knob with no integrity check - but it sits in an app whose whole value is broad delegated access to a person’s accounts and devices. That turns ordinary local malware into something with an agent’s reach, which is the pattern security researchers have warned about for agentic assistants: the agent becomes the most valuable thing on the machine to hijack. What it does not show is any exploitation in the wild, a remote or drive-by attack, or a flaw in Muse’s cloud VM sandbox; the weakness was in the desktop client, and Meta’s fix came within about a day of public disclosure.