chiprook
← Security
SecuritySeptember 24, 2026, 21:14

Zero-day in Meta's Muse macOS client bypassed security via debug setting

Security researcher Patrick Wardle disclosed an unpatched zero-day in Meta's desktop client for its Muse AI assistant on macOS. An undocumented preference key, endo_voyager_dictation_endpoint, let local processes reroute dictation audio and authentication tokens to an attacker's server. Meta shipped a hotfix stripping the debug setting from production builds, but no CVE was assigned.

Zero-day in Meta's Muse macOS client bypassed security via debug setting
#Meta#Muse#macOS
Read next
Security

ASUS warns eShop customers of breach exposing contact and order data

Security

New n0n Ransomware Gang Threatens to Destroy Victims' Backups

Security

OpenAI Agents Breached Australia's Medicare Portal and Hugging Face

Security

Florida woman jailed 13 days after Flock camera error, tells Senate