Today for AI

InfoQ 中文 · 10/8/2026, 3:50:05 AM

Meta Muse macOS Client Zero-Day Bypasses Permissions via Config Key

By 作者Olimpiu PopOriginal title: 苹果筑起的权限高墙,被 Meta AI 助手“借道”绕过
68AI Score
Executive Summary

Security researcher Patrick Wardle disclosed an unpatched zero-day vulnerability in Meta's Muse macOS client, allowing attackers to hijack voice dictation traffic by tampering with the endo_voyager_dictation_endpoint configuration key. The flaw enables non-privileged processes to bypass macOS permission prompts, stealing raw audio and authentication tokens to facilitate prompt injection and unauthorized actions. Meta has not yet issued a security advisory or requested a CVE.

SOURCE COVERAGEOriginal coverage

Contents3 sections

Muse macOS Client Contains Unpatched Zero-Day Vulnerability Stemming from the endo_voyager_dictation_endpoint Configuration Key, Which Can Be Tampered with by Unprivileged Processes, Leading to Voice Dictation Traffic Hijacking. Attackers Can Steal Audio Data and Session Tokens, and Execute Prompt Injections to Perform Unauthorized Operations. Meta Has Not Yet Issued a Security Advisory or Requested a CVE Number.

  • The vulnerability allows unprivileged local processes to silently overwrite critical configuration keys, bypassing macOS permission prompts.
  • The dictation feature leaks raw microphone audio and valid authentication tokens to attacker-controlled endpoints.
  • Once session credentials are obtained, attackers can perform prompt injections to drive the assistant to execute background tasks such as stealing local files.

Suitable for macOS security engineers, client architects, and AI application penetration testers.

Patrick Wardle, founder of the Objective-See Foundation and security researcher, disclosed an unpatched zero-day vulnerability affecting Meta’s newly released Muse macOS desktop client. Meta CEO Mark Zuckerberg had claimed that this autonomous AI assistant was built with privacy and security at its core from the outset; however, reports indicate that this vulnerability allows locally running software or shell commands to hijack the application. Through this attack vector, unprivileged software can leverage the broad permissions previously granted to the assistant by the user, bypassing macOS’s standard security boundaries. Since the company has not issued a formal security advisory nor coordinated with a CVE numbering authority, the vulnerability currently lacks an official CVE identifier.

The vulnerability stems from an undocumented configuration preference key named endo_voyager_dictation_endpoint. On macOS, local processes and arbitrary scripts running under an unprivileged user account can overwrite this configuration value without requiring elevated administrator privileges or triggering OS authorization prompts. Under normal operation, this parameter specifies the cloud server endpoint that receives voice dictation audio and returns transcription results. By simply modifying this setting, an attacker can stealthily redirect the assistant’s dictation traffic to a server under their direct control.

From an exploitation perspective, this vulnerability compromises both input confidentiality and account credentials. When users enable the dictation feature, the desktop client sends raw microphone audio and valid authentication tokens associated with the victim’s Muse account to the configured endpoint. Wardle demonstrated how an attacker could run a proxy server that captures authentication tokens and audio data while seamlessly forwarding legitimate traffic back to Meta’s servers, thereby avoiding detection. With valid session credentials and direct control over the command pipeline, attackers can also execute prompt injection attacks by appending hidden instructions within voice requests, forcing the assistant to perform unauthorized background tasks, such as exfiltrating local documents or WhatsApp message logs.

The technical significance of this vulnerability lies in its ability to amplify access privileges and erode platform trust boundaries. Operating systems like macOS rely on the Transparency, Consent, and Control (TCC) framework to restrict application access to hardware peripherals, files, contacts, and calendars. Since Muse is an agent capable of interacting with applications, calendars, emails, and files, users typically grant it extensive system permissions. Wardle noted that this vulnerability enables malicious actors to effectively turn a signed, trusted assistant into an attack surface by manipulating the agent, eliminating the need to develop complex standalone infostealer malware. A former Meta AI security engineering manager expressed similar architectural concerns, stating that they would not use the software due to risks inherent in deep integration.

Wardle released a proof-of-concept exploit named not-a-mused, demonstrating how to execute numerous commands via a compromised agent. This disclosure occurred shortly after Amazon banned Muse from accessing its shopping platform for violating automated agent access policies. Following public disclosure of the vulnerability, Meta deployed a hotfix for the macOS version of the Muse app. The fix removed this internal debugging preference setting from production client builds, preventing local modification of the dictation server target address.

The company treated this vulnerability as an internal configuration defect rather than following the formal CVE assignment process. David Singleton of Meta Superintelligence Labs described the issue as a local configuration problem requiring prior code execution capability, noting that the engineering team resolved it by quietly removing the internal debugging preference key from production builds. Comments from security professionals on related posts indicate that the community does not agree with this characterization. They pointed out that initial access can be easily obtained through social engineering lures like ClickFix, while bypassing Apple’s TCC framework has historically been highly complex. In broader engineering discussions on Hacker News and Reddit, observers noted that Meta’s consolidation of cross-device sync, full disk access, audio streaming, and private chat logs into a single unsandboxed, signed agent with modifiable debug endpoints effectively provides ordinary malware with a nearly effortless channel to bypass platform protections without triggering runtime alerts.

Meta's Muse: A Zero-Day Vulnerability in AI Model Serving

Meta has disclosed a critical zero-day vulnerability, dubbed "Muse," affecting its internal AI model serving infrastructure. The flaw allows attackers to bypass authentication mechanisms and execute arbitrary code on servers hosting large language models (LLMs).

Technical Details

The vulnerability stems from a race condition in the gRPC interceptor chain used for request validation. Specifically, under high-throughput conditions, the AuthMiddleware fails to properly synchronize with the RateLimiter, allowing unauthenticated requests to slip through during token bucket refills.

PYTHON
# Simplified representation of the vulnerable logic
class AuthMiddleware:
    def intercept(self, request):
        if not self.rate_limiter.is_available():
            # Race condition occurs here
            return self.handle_fallback(request) 
        return validate_token(request.token)

Impact and Mitigation

  • Affected Systems: All instances running Meta's proprietary inference engine version 2.4.x through 2.6.x.
  • Severity: Critical (CVSS 9.8).
  • Mitigation: Meta has released patch 2.6.1, which introduces atomic locking around the rate limiter state. Engineers are advised to upgrade immediately.

"This incident highlights the growing complexity of securing AI infrastructure, where traditional web security patterns may not suffice." — Meta Security Team

Recommendations for AI Engineers

  1. Audit Interceptor Chains: Ensure all middleware components handle concurrency safely.
  2. Monitor Throughput Anomalies: Set up alerts for unusual spikes in unauthenticated traffic.
  3. Update Dependencies: Regularly review and update internal libraries used for model serving.