NEWS · COMPANIES · #959
Zero-day in Meta’s Muse for macOS let local processes reroute dictation; hotfix removed debug key
Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse desktop client for macOS where an undocumented preference (endo_voyager_dictation_endpoint) could be overwritten by local, unprivileged processes to reroute microphone audio and steal Muse authentication tokens. Wardle published a proof-of-concept called not-a-mused; Meta released a hotfix that strips the internal debug preference from production builds but did not publicly coordinate a CVE.
KEY POINTS
- Security researcher Patrick Wardle disclosed a zero-day in Meta's Muse desktop client for macOS where an undocumented preference (endo_voyager_dictation_endpoint) could be overwritten by local, unprivileged processes to reroute microphone audio and steal Muse authentication tokens.
- Wardle published a proof-of-concept called not-a-mused; Meta released a hotfix that strips the internal debug preference from production builds but did not publicly coordinate a CVE.
- Because the flaw lets an attacker turn a signed, heavily‑permitted assistant into a stealthy conduit for audio exfiltration and session token theft, it undermines macOS platform protections and user trust in deeply integrated AI agents.
WHY IT MATTERS
Because the flaw lets an attacker turn a signed, heavily‑permitted assistant into a stealthy conduit for audio exfiltration and session token theft, it undermines macOS platform protections and user trust in deeply integrated AI agents.