Patrick Wardle’s proof of concept, not-a-mused, targeted an undocumented setting in Meta’s Muse for Mac. By changing where Muse sent dictated prompts for transcription, code already running on a user’s Mac could send that traffic to an attacker-controlled server and potentially capture the token used to authenticate the user’s Muse account. The flaw did not, on its own, let an attacker break into a Mac remotely.
8
11
How the dictation flaw worked
Muse’s endo_voyager_dictation_endpoint setting selected the destination for dictated prompts. Wardle found that a local app or Terminal command could change it without special macOS permissions. Once redirected, a prompt the user dictated could go to the attacker’s endpoint instead of Meta’s, exposing the voice traffic and authentication material. Exploitation therefore required code already running on the Mac and use of dictation; it was not a passive way to intercept every Muse conversation.
7
8
28
What Wardle demonstrated—and what remained a risk
Reporting on Wardle’s demonstration says a compromised Muse session obtained the location of a linked iPhone in Barcelona and initiated a Bluetooth Low Energy scan on that device. Those are specific demonstrated actions, not proof that every permission Muse might hold was exercised. The broader concern was that someone holding the account token could act through Muse and potentially use access the owner had already granted it to connected accounts and devices.
9
19
26
That distinction matters for consumers and enterprises alike: a modestly privileged local process could become a route into a much more capable assistant. For an organization, the question is not only whether an employee installed Muse, but what files, services and devices that installation made reachable.
8
9
19
Meta’s fix, Wardle’s warning and the Amazon block
Wardle later said Meta had patched the bug and thanked the company for the quick fix. Subsequent reporting says Meta also removed the internal setting that permitted the dictation endpoint to be changed. Wardle had urged users not to install Muse, although the provided accounts do not establish a detailed rationale for that advice or a specific prediction about future discoveries.
28
17
11
Amazon’s separate decision to block Muse from shopping on its site was not presented as a response to this vulnerability. Amazon told Adweek that Meta had not disclosed or obtained authorization for Muse’s shopping activity; reporting also says Amazon objected to the agent accessing its site without identifying itself.
22
24