Today for AI
HOT RADAR
agentHEAT 11.5°

AI CLUSTERED EVENT · 10/8/2026

Meta Muse macOS Client Zero-Day Bypasses Permissions via Config Key

1 reports archived1 independent sourcesupdated 10/8/2026, 3:50:05 AM
Synthesis & Latest Updates
1 Sources Cross-Validated

Security researcher Patrick Wardle disclosed an unpatched zero-day vulnerability in Meta's Muse macOS client, allowing attackers to hijack voice dictation traffic by tampering with the endo_voyager_dictation_endpoint configuration key. The flaw enables non-privileged processes to bypass macOS permission prompts, stealing raw audio and authentication tokens to facilitate prompt injection and unauthorized actions. Meta has not yet issued a security advisory or requested a CVE.

LATEST/Security researcher Patrick Wardle disclosed an unpatched zero-day vulnerability in Meta's Muse macOS client, allowing attackers to hijack voice dictation traffic by tampering with the endo_voyager_dictation_endpoint configuration key. The flaw enables non-privileged processes to bypass macOS permission prompts, stealing raw audio and authentication tokens to facilitate prompt injection and unauthorized actions. Meta has not yet issued a security advisory or requested a CVE.

TIMELINECoverage timeline

Total 1 reports · Latest first
  1. InfoQ 中文T2·68 pts

    Meta Muse macOS Client Zero-Day Bypasses Permissions via Config Key

    Original: 苹果筑起的权限高墙,被 Meta AI 助手“借道”绕过

    • Non-privileged local processes can silently overwrite critical Muse client configuration keys, hijacking traffic without triggering macOS authorization prompts.
    • Attackers can simultaneously steal raw microphone audio and valid authentication tokens, enabling undetected man-in-the-middle attacks.
    • With session credentials, attackers can use prompt injection to drive the AI assistant to perform malicious background tasks like file exfiltration.
Meta Muse macOS Client Zero-Day Bypasses Permissions via Config Key | AI Clustered Intelligence | Today for AI