Zero-day in Meta’s Muse for macOS let local processes reroute dictation; hotfix removed debug key
Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse desktop client for macOS where an undocumented preference (endo_voyager_dictation_endpoint) could be overwritten by local, unprivileged processes to reroute microphone audio and steal Muse authentication tokens. Wardle published a proof-of-concept called not-a-mused; Meta released a hotfix that strips the internal debug preference from production builds but did not publicly coordinate a CVE.