Meta's Muse Dictation Bug Lets Malware Reach Your iPhone
Meta's Muse exposed a local setting that lets malware redirect your Mac's cloud dictation to an attacker's server—reaching your iPhone, email, WhatsApp, and more. 🎙️ Researcher Patrick Wardle found the undocumented endo_voyager_dictation_endpoint in five days; no trojan or privilege escalation needed. Once any code runs under your user account, the attack surface expands to connected devices. Meta patched it but disclosed no CVE details. Skip the flashy promise—is handing over your voice recordings, tokens, and location worth cloud dictation's convenience? 🤔Let's be honest about something everyone in the security world is thinking: Meta rolled out a personal AI assistant that lives on your Mac, then discovered five days after launch that a local malware program could hijack it to spy on your iPhone. The bug wasn't exotic. It wasn't a nation-state exploit or a worm with clever self-propagation. It was a setting — an undocumented one — that any software running under your user account can flip.
That's the whole story. And it's a bit embarrassing.
The Setting Nobody Talked About
Researcher Patrick Wardle of the Objective-See Foundation published the findings on September 21, just 13 days after Muse launched on September 8. The culprit is an undocumented configuration called endo_voyager_dictation_endpoint. In plain English, that's the server address your Mac's voice dictation sends your recordings to.
Meta chose cloud-based dictation over Apple's on-device processing. That's the design decision that made the whole mess possible. When you dictate to Muse, the audio gets shuttled to Meta's servers for transcription. And because the routing address is stored in an unsecured, undocumented setting, any piece of malware already on your machine can redirect that traffic to whatever server the attacker controls.
No separate trojan needed. No privilege escalation. Your dictation, your tokens, and your connected-app permissions now belong to someone else.
The Reach Goes Well Beyond Dictation
Here's where the "low impact" narrative falls apart. Wardle demonstrated that a compromised Muse session can reach every other device linked to your Muse account. That includes your iPhone. In his proof-of-concept, he retrieved the iPhone's location data and initiated Bluetooth Low Energy scans from the Mac session.
Think about what that means for the "it's just a local bug" defense. Yes, it requires code execution under your user account — not a remote exploit. But once that foothold exists, the attack surface expands to your phones, your email, your WhatsApp, your calendar, and anything else Muse's cross-app permissions touch. Attackers can capture your agent token, inject prompts, and exfiltrate photos and files.
The breach isn't the malware on your Mac. The breach is the assistant turning on the rest of your life.
Meta's Response: A Hotfix With No Details
Meta says it has patched the issue. Details on the specific build or CVE remain... undisclosed. Amazon, for what it's worth, has already pulled Muse's shopping feature while it investigates. That tells you how much confidence a major partner has in the remediation right now.
Meta also leans on its "Muse Secure VM" as a safety framework. The design is meant to sandbox the assistant from your system. The problem, as Wardle's work illustrates, is that the assistance itself — the very feature that convinces people to let it in — can be turned against its user.
The Pattern You Should Notice
Meta has stated publicly, per the reporting, that it "predicted security issues" due to the extensive permissions Muse requires. Predicted. Launched anyway. And shipped a cloud-dictation architecture that undermines the very isolation its marketing claims to provide.
It's a familiar playbook: ship the flashy AI agent, promise a secure VM, and let external researchers find the holes the internal process apparently flagged in advance. Wardle found this one in five days. There are likely more.
The Takeaway
Muse isn't going away. AI assistants with broad integrations are the trajectory of consumer software. But this episode shows what happens when a vendor's ambition outpaces its security literacy. The bug was trivial, the reach was broad, and the responsible party responded only after public disclosure.
If you're running Muse on a Mac, you might ask whether the convenience of cloud dictation is worth handing your voice recordings, account tokens, and device location to anything already lurking on your system. Meta certainly isn't going to ask that question for you.
Comments ()