EventCybersecuritySeptember 21, 2026

Meta patches Muse zero-day that let attackers hijack the AI agent

Read original source →arstechnica.com

Security researcher Patrick Wardle showed the undocumented macOS setting endo_voyager_dictation_endpoint could redirect Muse dictation to an attacker's endpoint, handing over the account token. Meta patched it within hours of the Ars Technica report, calling it a local privilege escalation, not a remote exploit.

People · Patrick Wardle

How this story unfolded

2 days · 4 reports · 4 of 5 shown

  1. Sep 21
  2. Sep 22
  3. Sep 23

More stories today

Open the live feed