Meta Offered $300,000 to Not Find This Bug
A researcher broke Meta's 'Secure VM' with an undocumented config setting the same week Muse plugged into Shopify checkout. The bounty program didn't stop him from going public.

Mark Zuckerberg spent September telling everyone Muse was different. Built for privacy. Built for security. A personal agent you could trust with your files, your accounts, your dictation. Patrick Wardle spent the same month proving that trust was a marketing claim, not an architecture.
Wardle, the founder of Objective-See, published a proof-of-concept called "not-a-mused" this week. An undocumented setting, endo_voyager_dictation_endpoint, can be altered by any local process already running on the machine. Change that value and you redirect Muse's dictation traffic to a server you control. Malware could then assume the permissions the user granted to Muse, turning an application-level trust relationship into an opportunity for an attacker already present on the endpoint to amplify access.
This is not remote code execution. It requires malware already on the Mac. That's a real constraint.
Here's what isn't a constraint: once that foothold exists, a compromised agent inherits the extensive permissions and connected-service access that users entrusted to Muse. Wardle's demonstrations reached further than stolen tokens. Separate demonstrations reportedly showed the compromised account identifying linked devices and directing an online iPhone to return location information or initiate a Bluetooth Low Energy scan. A local config bug on a laptop reached into someone's pocket.
The marketing gap
Meta didn't undersell Muse's security. The company said the system uses isolated execution, least-privilege access, and a dedicated security layer called Sentinel which it described as the sole authority for connector actions and network egress.
Translation: we built the permission model, we named it something that sounds like a bouncer, and we're asking you to take our word that it works.
Wardle didn't. He found the gap with a local process and an undocumented config key.
Meta backed that confidence with a bug bounty paying up to $300,000 for critical findings. Wardle went public instead. A public zero-day is itself data about whether researchers trust the disclosure process, and it's not flattering.

Same week, different stakes
While this unfolded, Shopify was rolling agentic checkout through Shop Pay into every Shopify-powered store, integration automatic for merchants with no extra setup required. Muse also connects to Stripe Link, giving it saved payment access across more than 1 million businesses that accept Link. Amazon, meanwhile, blocked Meta's Muse from shopping on Amazon.com entirely.
Two large platforms looked at the same agent and reached opposite risk conclusions in the same week.
The vulnerability doesn't touch payment code directly. But the architecture it exposes—an agent whose stolen session inherits every permission and connected account a user granted it—is the exact architecture now wired into checkout. You don't need the specific exploit to be payment-adjacent to worry about the pattern it reveals.
Muse hit No. 1 free app in Apple's US App Store within a week of launch. Adoption outran audit.
What to watch: whether Meta discloses how long the endpoint issue was live before Wardle's disclosure; what Wardle's full technical breakdown at Objective by the Sea in November reveals; whether Shopify or Stripe impose isolation requirements on Muse's connector access; and whether any enterprise actually pauses a Muse integration rather than waiting for the patch email.
- Meta's Muse AI Agent 0-Day Vulnerability Allows Attackers to hijack the tool and Inject Malware
- Security researcher says don't install Meta's Muse AI assistant - iTnews
- [RegisterSec] Meta Muse AI app flaw lets local malware redirect dictation traffic
- Meta's Muse AI agent faces security scare, raises alarms over AI agent safety
- Meta's Muse AI 0-Day Lets Hackers Hijack Dictation Traffic and Inject Malicious Prompts
- Shopify and Muse partner to bring agentic checkout to all Shopify stores
- Shopify adds Meta Muse to agentic AI strategy | American Banker
- After Amazon Blocks Meta's Muse Agent, Shopify Says It'll Integrate Muse
- Meta Muse Connects AI Shopping, Catalogs, and Checkout – P3 Media
- Meta's Muse AI Assistant Exposes Massive Zero-Day Vulnerability – Archyde
- Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware | Cryptika Cybersecurity
- Alisa Esage
- Benjamin Kunz Mejri
- Mark Zuckerberg Says 'More Partnerships' Coming as Meta Teams With Shopify to Power AI Purchases: 'Shoppe - Benzinga
- Shopify (SHOP.US) partners with Meta (META.US) to launch AI-powered payment solutions, aiming to displace the traditional role of banks.
- Meta Partners With Shopify to Bring Shop Pay Checkout to Muse AI - EconoTimes
- Meta's Muse AI Hits Top US App Charts and Partners With Shopify for Checkout - Time News
- Meta tests AI shopping tool in bid to compete with OpenAI and Google