EventCybersecuritySeptember 21, 2026

Meta patches Muse zero-day that let attackers hijack the AI agent

Read original source →arstechnica.com

Security researcher Patrick Wardle showed a hidden Muse setting, endo_voyager_dictation_endpoint, let any local process redirect dictation to an attacker's endpoint and steal the account token. Meta patched the macOS app within hours of the Ars Technica report; Amazon began blocking Muse from its site Sunday.

People · Patrick Wardle

How this story unfolded

3 days · 7 reports · 2 community posts · 9 of 12 shown

  1. Sep 21
  2. Sep 22
  3. Sep 23
  4. Sep 24

More stories today

Open the live feed