Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Meta Muse Agent Hijack 2026: How One Undocumented…
Breach analysis Incident: 21 Sep 2026

Meta Muse Agent Hijack 2026: How One Undocumented Setting Let Local Malware Steal an AI Agent’s Authentication Token

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 8 min read
Category: AI agents NHI
Attack route: Vulnerability exploit Identities: AI agent Session token
On this page

On 21 September 2026, security researcher Patrick Wardle disclosed a zero-day in the Mac app of Muse, the personal AI agent Meta had launched two weeks earlier. An undocumented setting, endo_voyager_dictation_endpoint, could be changed by any unprivileged local process. Doing so redirected Muse's voice dictation to an attacker-controlled server. From there, Wardle showed, an attacker could capture dictated prompts, inject prompts that Muse trusts and executes, steal Muse authentication material, and use whatever access the user had granted the agent. That access could include messages, email and finances. Meta hot-fixed the flaw the next day. No exploitation has been reported. The case shows how a personal AI agent turns ordinary local malware into something far more powerful: the agent's own identity and permissions become the attacker's.

Key takeaways

  • Wardle's proof of concept, "not-a-mused", shows that Muse exposed an undocumented setting that a local attacker or malware could change "without special privileges", redirecting dictation traffic to the attacker.
  • The README lists the impact: capture of dictated audio and prompts, prompt injection into Muse, "theft of Muse authentication material", and abuse of whatever access the user has granted Muse.
  • The attack is local: an attacker must already run code as the user. Its value is amplification, because Muse can have far broader access than ordinary malware, and the proof of concept uses a subset of more than 50 commands Muse exposes.
  • According to Unite.ai's report of Wardle's posts, Meta hot-fixed the flaw on 22 September. Wardle also described a remote route through a ClickFix-style lure and control of the victim's other Muse devices, including iOS.
  • The identity lesson: an AI agent's session and tokens are high-value credentials, and any unauthenticated setting that can redirect its traffic is a route to all of the user's delegated access.

At a glance

OrganisationMeta (Muse personal AI agent, macOS app and connected devices)
WhenMuse launched 8 September 2026; flaw disclosed 21 September 2026; hot-fix reported 22 September 2026
AttackerNone known. Found and disclosed by security researcher Patrick Wardle, with a public proof of concept
Entry pointAn undocumented Muse setting, endo_voyager_dictation_endpoint, writable by any local process running as the user
Identities abusedThe Muse agent and its authentication material, and the access the user had delegated to the agent across connected services and devices
ImpactPotential theft of agent authentication tokens and prompts, prompt injection, and abuse of delegated access; no confirmed real-world victims
CategoryAgentic AI and AI agents, NHI. Incident class: agent vulnerability (vulnerability, no confirmed breach)

What happened

Meta launched Muse on 8 September 2026 as a personal AI agent that can act across a user's apps and accounts. According to Unite.ai, Meta's launch post described a security design that assumes the agent may be under attack. Tools run in an isolated runtime cell, and a separate host-side component called Sentinel controls connector permissions and network egress. It inserts credentials just in time so that the agent never sees real tokens. Meta also opened a bug bounty with awards of up to $300,000.

On 21 September, Wardle published a thread on X and a proof-of-concept repository called "not-a-mused". The README describes "a local Muse vulnerability 0day that can let an unprivileged local process redirect Muse's dictation traffic and abuse the trust/access granted to the app". The weakness was the undocumented setting endo_voyager_dictation_endpoint. Once malware changed it, a user clicking Muse's microphone button and dictating a prompt sent the dictation to the attacker's server instead of Meta's. The README lists the consequences: "Capture of dictated audio/prompts", "Prompt injection into Muse", "Theft of Muse authentication material" and "Abuse of whatever access the user has granted Muse". The proof of concept implements "a subset of the 50+ commands exposed by Muse".

The README is explicit that this is a local attack: "an attacker must already be able to execute code as the local user." According to Unite.ai, Wardle framed the risk as amplification. Muse can have much broader access than ordinary local malware, so hijacking it hands the attacker the user's messages, email and financial connections. Unite.ai also reports that Wardle said an attacker on one Mac could invisibly task the user's other Muse devices, including the iOS client. It adds that a ClickFix-style lure, in which a victim is tricked into running a single command, could have delivered the hijack remotely. On 22 September, Wardle posted "Hooray, hot-fixed!". David Singleton of Meta Superintelligence Labs confirmed the fix, telling users, as quoted by The Register: "This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user's machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low... Nonetheless, we have issued a hotfix to the app to address the issue." Wardle told The Register that AI apps can undo operating system protections because "they have so much access if you configure them to be useful. They basically could do anything on your computer."

Timeline

DateEvent
8 September 2026Meta launches Muse and describes its security architecture and bug bounty.
21 September 2026Patrick Wardle discloses the dictation-endpoint zero-day on X and publishes the "not-a-mused" proof of concept.
22 September 2026Wardle reports that Meta has hot-fixed the flaw.

How it happened: the identity attack path

  1. Code already on the Mac. The attack starts with malware or an attacker running as the user, the kind of foothold infostealers and ClickFix lures routinely provide.
  2. An unprotected, undocumented setting. Muse read its dictation endpoint from a setting any local process could change, with no integrity check or authentication.
  3. Agent traffic redirected. Dictated prompts went to the attacker's server, which could read them and send back injected prompts that Muse trusted and executed.
  4. Agent credentials captured. The traffic carried Muse authentication material. With it, an attacker could drive the agent directly and invisibly.
  5. Delegated access inherited. Everything the user had connected to Muse became reachable through the hijacked agent, including other Muse-enabled devices.

Impact

  • Potential: theft of prompts, audio and Muse authentication material, prompt injection, and abuse of the user's delegated access to messages, email, finances and connected devices.
  • Scope: Mac users of Muse between its 8 September launch and the 22 September hot-fix.
  • Confirmed: no exploitation reported.

What this means for NHI and AI agent security

Personal AI agents hold delegated access to a user's digital life, and they authenticate with tokens and sessions of their own. That makes an agent's credentials some of the most valuable secrets on a device. Muse was designed with care: an isolated runtime, a separate permission authority and just-in-time credential insertion. Yet one undocumented configuration value that local code could change was enough to route traffic, and authentication material, around those protections.

The wider lesson is about the agent's own identity. Controls that stop the model seeing real tokens do not help if the channel between the app and its backend can be redirected. Agent sessions need binding to the device and endpoint, configuration that cannot be silently changed, and monitoring for tokens used from unexpected places. Our Token and Session Security Guide and Browser and Computer-Use Agent Guide cover these controls.

Recommendations

  • Update Muse. Make sure the Mac app is on a version released after the 22 September hot-fix.
  • Protect agent configuration. Agent vendors should sign or lock endpoint settings, ignore undocumented overrides in production, and pin backend endpoints.
  • Bind agent sessions. Tie agent tokens to the device and backend, so a token captured by a redirected endpoint cannot be replayed elsewhere. See our Token and Session Security Guide.
  • Limit what personal agents can reach. Grant agents only the accounts and actions they need, and keep confirmation steps for sensitive actions. See our AI Agent Authorisation Guide.
  • Treat endpoint malware as an agent threat. Infostealers and ClickFix lures now lead straight to AI agents. Include agent apps in endpoint protection and incident response. See our Shadow AI Discovery Guide.

Frequently asked questions

What was the Meta Muse vulnerability?

An undocumented setting, endo_voyager_dictation_endpoint, in the Muse Mac app could be changed by any local process without special privileges. That redirected dictation to an attacker's server, enabling prompt capture, prompt injection, theft of Muse authentication material and abuse of the user's delegated access.

Could it be exploited remotely?

The proof of concept is a local attack that needs code already running as the user. According to Unite.ai's report of Wardle's posts, a ClickFix-style lure that tricks a user into running one command could have delivered it remotely.

Has Meta fixed it?

Yes. Meta issued a hotfix on 22 September 2026, a day after Wardle's disclosure, and described the practical risk as low because malicious code must already be running on the Mac. No exploitation has been reported.

Meta AI Instagram account takeover · Meta Muse Spark evaluation breach 2026 · Sentry MCP Agentjacking 2026 · Agentic AI Identity Guide · Token and Session Security Guide

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as personal agents hold tokens and delegated access across a user's accounts and devices. Our NHI Foundation Level Training Course gives teams the practical grounding to govern that access.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org