Vulnerabilities · 3h ago

Meta Muse Privacy Claims Meet Local Malware

Meta’s Muse AI app has a flaw that lets local malware on the same device redirect dictation traffic, according to The Register. That means the app’s privacy controls can still be undercut after the app is running, even if the user believes the protected environment is in charge.

The issue is not a remote break-in; it is an endpoint compromise that can slip voice prompts onto a path the user did not intend. In plain terms, Muse may still look private while the spoken words are being captured elsewhere, so the confidentiality risk lands on the content of the dictation itself.

For anyone using Muse on machines where local malware is plausible, the exposure sits at the host level rather than inside the app’s own trust boundary. The fix, if one follows from this report, is about the device’s integrity; the reporting does not describe a versioned patch or confirmed exploitation.

Timeline

Sources

2 sources covering this story

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories