{
  "id": 9052823,
  "title": "Meta Muse AI app flaw lets local malware redirect dictation traffic",
  "url": "https://urgent.news/2026/09/21/meta-muse-ai-app-flaw-lets-local-malware-redirect-dictation-traffic-9052823",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-21T19:59:52.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/ai-and-ml/2026/09/21/meta-muse-ai-app-flaw-lets-local-malware-redirect-dictation-traffic/5297980"
  },
  "original_language": "en",
  "account": "The Meta Muse AI app for macOS has been found to have a flaw that could allow local malware to gain more access than expected. Security researcher Patrick Wardle has developed a proof-of-concept called not-a-mused to demonstrate the vulnerability. The issue stems from an undocumented setting called endo_voyager_dictation_endpoint, which an attacker can manipulate to redirect dictation traffic away from the intended destination. This could lead to prompt injection, theft of authentication material, and abuse of the user's granted access. The flaw requires local code execution, making it a privilege escalation vulnerability rather than a concern for remote attackers. Wardle compared the situation to living in an apartment building where a bad neighbor could gain access to all units, highlighting the broad access granted to local malware. Apple's Transparency, Consent, and Control (TCC) framework and privilege separation have helped manage sensitive data access, but Wardle expressed concern that AI apps often require extensive permissions, potentially breaking operating system security controls. He questioned whether AI companies are prioritizing security, suggesting that endpoint detection and response (EDR) software struggles to distinguish between legitimate commands and those from attackers. Wardle recommended that Meta use Apple's on-device local dictation API instead of its own service to mitigate the risk, citing a potential data privacy issue. Meta declined to comment on the matter.",
  "summary": "Ad biz promises users control while bug could expose voice prompts",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 6,
    "also_reported_by": [
      {
        "outlet": "Business Insider",
        "title": "Amazon is keeping Meta’s Muse out of its shopping carts",
        "url": "https://urgent.news/2026/09/21/amazon-is-keeping-metas-muse-out-of-its-shopping-carts",
        "published": "2026-09-21T14:32:43.000Z"
      },
      {
        "outlet": "The Register Science",
        "title": "Meta Muse AI app flaw lets local malware redirect dictation traffic",
        "url": "https://urgent.news/2026/09/21/meta-muse-ai-app-flaw-lets-local-malware-redirect-dictation-traffic",
        "published": "2026-09-21T19:59:52.000Z"
      },
      {
        "outlet": "CNET",
        "title": "No Shirt, No Shoes, No Service: Amazon Blocks Meta’s Muse AI From Shopping",
        "url": "https://urgent.news/2026/09/21/no-shirt-no-shoes-no-service-amazon-blocks-metas-muse-ai-from-shopping",
        "published": "2026-09-21T20:27:31.000Z"
      },
      {
        "outlet": "The Business Times - Companies & Markets",
        "title": "Meta’s new Muse AI app tops charts, draws strong reviews",
        "url": "https://urgent.news/2026/09/22/metas-new-muse-ai-app-tops-charts-draws-strong-reviews",
        "published": "2026-09-22T00:36:57.000Z"
      },
      {
        "outlet": "CNBC World",
        "title": "CNBC Daily Open: AI trade goes Meta after Muse launch",
        "url": "https://urgent.news/2026/09/22/cnbc-daily-open-ai-trade-goes-meta-after-muse-launch",
        "published": "2026-09-22T06:09:14.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}