Two Muse Flaws in Five Days: A Hacker's Zero-Day and a SEV-2 Bug That Reached Into Users' Cloud VMs
Patrick Wardle's disclosure let local malware hijack Meta's Muse agent on the Mac; days later an outside researcher found a flaw rated SEV-2 that could expose the personal cloud VM holding a user's emails and files. Both were fixed fast — but the pattern they expose is the real story.
On September 25, The Information reported that Meta had quietly strengthened the safety warning inside Muse, its fast-growing personal AI agent, after an outside security researcher discovered a vulnerability that could let an attacker reach a user’s most sensitive personal data. The flaw — reported through Meta’s bug bounty program and not previously disclosed — could have allowed access to a user’s dedicated virtual machine, the individualized cloud account where Muse stores the emails, files, and connected-service data it works with on the user’s behalf. Meta’s internal incident report classified it as SEV-2, the company’s third-highest severity level on a five-point scale, typically reserved for incidents with significant impact.
The disclosure lands barely five days after security researcher Patrick Wardle published a separate, more public flaw in Muse’s Mac app. Two serious findings in one week would be rough for any product. For an agent that holds login credentials, reads email, moves money, and — as of Meta Connect 2026 — is headed for users’ smart glasses and Macs, it sketches a steeper curve: the more capability an agent accumulates, the more every bug becomes a skeleton key.
Flaw #1: Hijacking the dictation endpoint
Wardle’s disclosure, posted as an X thread on September 21 at 14:42 UTC and paired with a proof-of-concept repository pointedly named “not-a-mused,” described an unprivileged local process redirecting the Muse Mac app’s dictation traffic to an attacker-controlled endpoint. The root cause was an undocumented setting — endo_voyager_dictation_endpoint — that a local attacker or ordinary malware could modify without any special privileges. When the user clicked Muse’s microphone button and dictated a prompt, the audio went to the attacker instead of Meta.
The consequences chain from there. The attacker captures dictated audio and prompts; injects prompts that Muse trusts and executes; steals Muse authentication material to control the agent directly and invisibly; and inherits whatever access the user has granted the agent — messages, email, finances. The PoC’s README summarizes the impact in one line: “Muse’s access can potentially become the attacker’s access.”
Two details made the finding worse than a simple local bug. First, the exposure spans devices: once a Mac is exploited, an attacker can interact with any of the user’s other connected devices running Muse, including invisibly tasking the iOS client. Second, a remote vector existed as well — a ClickFix-style attack requiring only a single user-run command could deliver the hijack and give a remote attacker Muse-scoped control across all of a victim’s Muse-enabled devices. Wardle called the flaw trivial to exploit. To Meta’s credit, it hot-fixed the issue within roughly a day; Wardle confirmed the patch on September 22 with a laconic “Hooray, hot-fixed!” and noted he would share more findings at the Objective by the Sea v9 security conference.
Flaw #2: The SEV-2 VM exposure
The second flaw, reported separately through the bug bounty program and revealed by The Information’s report on an internal Meta incident document, is quieter but arguably more alarming for what it touches. Each Muse user gets a dedicated, individualized cloud-based virtual machine that holds the agent’s working data — including personal emails and files. The vulnerability could have let an attacker access that VM directly, bypassing the agent’s permission theater entirely and going straight to the vault. Meta rated it SEV-2 on its five-point internal scale — high severity, significant impact.
Meta’s response, per the report, was to add a clearer in-app safety warning to Muse. The company did not immediately respond to a Reuters request for comment on the story.
Meta’s security design, and its limits
To be fair to Meta, Muse’s architecture is more deliberately hardened than most consumer AI software. The agent’s daemon and its tools run inside a systemd-nspawn runtime cell isolated from the host system. A separate host-side component called Sentinel acts as the sole permission authority for connector actions and all network egress. Credentials for connected services live in the user’s VM, and Sentinel performs just-in-time credential insertion at the network boundary — the model itself never sees real tokens. Each user’s VM is isolated from other users’ agents, passwords sit in a Secure Credentials Store, and important actions like sending an email or making a purchase require explicit confirmation. Crucially, Meta documents that these checks operate separately from the AI model, so they don’t depend on the model recognizing a malicious instruction on its own.
That design assumes the perimeter holds. Both September flaws illustrate where it thins. Wardle’s bug sat in the seam between the Mac client and the agent’s trust model — the dictation path treated a mutable local setting as if it were infrastructure. The SEV-2 flaw sat in the cloud tier where the isolation between “the user’s data” and “an attacker” apparently had a gap. A security architecture that assumes the agent may be under attack still has to enumerate every path an attacker can take, and enumeration is exactly where fast-shipped agent software tends to fail.
Meta is also paying for outside eyes: the Muse bug bounty program is open to anyone, with awards up to $300,000 for qualifying security flaws, including up to $130,000 for successful prompt-injection attempts that affect a single user. Both September findings arrived through exactly that channel — Wardle’s disclosure and the SEV-2 report are, in a sense, the bounty program working as designed. A planned Muse Confidential VM, designed to cryptographically and verifiably prevent even Meta from accessing a user’s VM data, is promised later this year.
Why the timing stings
The backdrop makes the story sharper. Muse launched on September 8 and has been racing up the charts since — Sensor Tower estimates roughly 2.8 million downloads in its first two weeks, with the app topping free-app rankings in the United States and Canada. At Meta Connect 2026 the company announced Muse is coming to its AI glasses, getting its own digital avatar, and gaining the ability to run a user’s Mac. Meta shares hit a 52-week high near $779.82 in the days after launch.
Every one of those milestones increases the blast radius of a security bug. A dictation-hijack flaw in an app used by thousands of early adopters is a research finding; the same flaw in an agent that runs on your glasses, reads your inbox, and holds your payment credentials is an incident. The FTC’s chair said this week that developers should answer for their agents’ actions — a posture that turns engineering hygiene into regulatory exposure.
None of this is unique to Meta. Muse is simply the highest-velocity test case yet of a question the whole industry is fumbling toward: when software graduates from “tool” to “delegate,” the old tolerance for bugs — patch, move on, ship — stops being adequate. The two flaws were found and fixed in under a week, which is genuinely fast. But the pattern is the point: agents concentrate access, and concentrated access attracts exactly the attackers who are best at finding seams. The bug bounty’s $300,000 ceiling is Meta betting that it can buy every seam before someone else sells one. Two weeks in, that bet is still live.
Sources
- [1] https://www.straitstimes.com/world/united-states/meta-bolsters-muse-safety-warning-after-security-vulnerability-found-the-information-reports
- [2] https://www.theinformation.com/briefings/exclusive-meta-bolsters-muse-safety-warning-security-vulnerability-found
- [3] https://www.unite.ai/meta-hot-fixes-muse-zero-day-that-let-attackers-hijack-the-ai-agent/
- [4] https://cybersecuritynews.com/metas-muse-ai-agent-0-day-vulnerability/
- [5] https://www.cnet.com/tech/services-and-software/metas-muse-ai-agent-zero-day-cybersecurity-bug-patched/
- [6] https://www.esecurityplanet.com/news/news-meta-muse-ai-agent-security-flaw/