Meta hotfixes a Muse flaw that let local malware redirect the AI agent's dictation to an attacker's server
A developer setting left in the macOS app's local preferences could be changed by other programs, putting at risk an agent that handles users' email, travel and shopping.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.
Meta has patched a zero-day vulnerability in the macOS app for Muse, the personal AI agent it launched on September 8. Muse can send emails, book travel, shop and track goals. To do that, users give it access to a wide range of apps, accounts and device features. David Singleton of Meta Superintelligence Labs said on X shortly after midnight Tuesday that the company had issued a hotfix. According to Singleton, the flaw involved Muse's dictation feature, which sends audio to Meta's servers for transcription instead of processing it on the Mac. The shipped app included an internal setting, meant for debugging and development, that let developers change the server endpoint used for dictation. That setting was stored in the app's local preferences, where other programs running under the user's account could change it. An attacker who already had code running on the Mac could therefore redirect dictation traffic to a server they controlled. The Verge reported that the exploit required local access but could give attackers access to users' Muse accounts. The flaw did not allow remote compromise on its own. Still, it shows how a leftover development option can become a route into an agent that holds broad access to a person's accounts, two weeks after a mass-market launch.