◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL
THE DIGITAL ALCHEMIST
SecurityIMPACT 70

Meta Offered $300,000 to Not Find This Bug

A researcher broke Meta's 'Secure VM' with an undocumented config setting the same week Muse plugged into Shopify checkout. The bounty program didn't stop him from going public.

2026-09-225 MIN READ#Meta · #Muse · #AI agents · #zero-day · #Shopify · #agent security
The Digital Alchemist
The Digital Alchemist

Mark Zuckerberg spent September telling everyone Muse was different. Built for privacy. Built for security. A personal agent you could trust with your files, your accounts, your dictation. Patrick Wardle spent the same month proving that trust was a marketing claim, not an architecture.

Wardle, the founder of Objective-See, published a proof-of-concept called "not-a-mused" this week. An undocumented setting, endo_voyager_dictation_endpoint, can be altered by any local process already running on the machine. Change that value and you redirect Muse's dictation traffic to a server you control. Malware could then assume the permissions the user granted to Muse, turning an application-level trust relationship into an opportunity for an attacker already present on the endpoint to amplify access.

This is not remote code execution. It requires malware already on the Mac. That's a real constraint.

Here's what isn't a constraint: once that foothold exists, a compromised agent inherits the extensive permissions and connected-service access that users entrusted to Muse. Wardle's demonstrations reached further than stolen tokens. Separate demonstrations reportedly showed the compromised account identifying linked devices and directing an online iPhone to return location information or initiate a Bluetooth Low Energy scan. A local config bug on a laptop reached into someone's pocket.

The marketing gap

Meta didn't undersell Muse's security. The company said the system uses isolated execution, least-privilege access, and a dedicated security layer called Sentinel which it described as the sole authority for connector actions and network egress.

Translation: we built the permission model, we named it something that sounds like a bouncer, and we're asking you to take our word that it works.

Wardle didn't. He found the gap with a local process and an undocumented config key.

Meta backed that confidence with a bug bounty paying up to $300,000 for critical findings. Wardle went public instead. A public zero-day is itself data about whether researchers trust the disclosure process, and it's not flattering.

The Digital Alchemist
The Digital Alchemist
Muse Bug Bounty Payouts
$130,000Prompt Injection→$300,000Max Critical Finding+131%
Meta's Muse bug bounty tiers, per Cryptobriefing reporting on the program's reward structure.

Same week, different stakes

While this unfolded, Shopify was rolling agentic checkout through Shop Pay into every Shopify-powered store, integration automatic for merchants with no extra setup required. Muse also connects to Stripe Link, giving it saved payment access across more than 1 million businesses that accept Link. Amazon, meanwhile, blocked Meta's Muse from shopping on Amazon.com entirely.

Two large platforms looked at the same agent and reached opposite risk conclusions in the same week.

The vulnerability doesn't touch payment code directly. But the architecture it exposes—an agent whose stolen session inherits every permission and connected account a user granted it—is the exact architecture now wired into checkout. You don't need the specific exploit to be payment-adjacent to worry about the pattern it reveals.

Muse hit No. 1 free app in Apple's US App Store within a week of launch. Adoption outran audit.

What to watch: whether Meta discloses how long the endpoint issue was live before Wardle's disclosure; what Wardle's full technical breakdown at Objective by the Sea in November reveals; whether Shopify or Stripe impose isolation requirements on Muse's connector access; and whether any enterprise actually pauses a Muse integration rather than waiting for the patch email.

Sources
  1. Meta's Muse AI Agent 0-Day Vulnerability Allows Attackers to hijack the tool and Inject Malware
  2. Security researcher says don't install Meta's Muse AI assistant - iTnews
  3. [RegisterSec] Meta Muse AI app flaw lets local malware redirect dictation traffic
  4. Meta's Muse AI agent faces security scare, raises alarms over AI agent safety
  5. Meta's Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts
  6. Shopify and Muse partner to bring agentic checkout to all Shopify stores
  7. Shopify adds Meta Muse to agentic AI strategy | American Banker
  8. After Amazon Blocks Meta's Muse Agent, Shopify Says It'll Integrate Muse
  9. Meta Muse Connects AI Shopping, Catalogs, and Checkout – P3 Media
  10. Meta's Muse AI Assistant Exposes Massive Zero-Day Vulnerability – Archyde
  11. Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware | Cryptika Cybersecurity
  12. Alisa Esage
  13. Benjamin Kunz Mejri
  14. Mark Zuckerberg Says 'More Partnerships' Coming as Meta Teams With Shopify to Power AI Purchases: 'Shoppe - Benzinga
  15. Shopify (SHOP.US) partners with Meta (META.US) to launch AI-powered payment solutions, aiming to displace the traditional role of banks.
  16. Meta Partners With Shopify to Bring Shop Pay Checkout to Muse AI - EconoTimes
  17. Meta's Muse AI Hits Top US App Charts and Partners With Shopify for Checkout - Time News
  18. Meta tests AI shopping tool in bid to compete with OpenAI and Google
← back to the feed
NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%