Critical 0-Day in Meta Muse AI Agent Lets Attackers Inject Malware
Key Takeaways A newly discovered zero-day vulnerability in Meta’s Muse AI agent for macOS allows local attackers to hijack the assistant. The flaw enables interception of user dictation, injection of...
Key Takeaways
- A newly discovered zero-day vulnerability in Meta’s Muse AI agent for macOS allows local attackers to hijack the assistant.
- The flaw enables interception of user dictation, injection of malicious commands, and theft of authentication tokens.
- While it requires initial local access, the vulnerability amplifies the capabilities of low-privilege malware by leveraging Muse’s extensive permissions.
- No official patch is currently available from Meta, necessitating immediate user mitigation steps.
A critical zero-day vulnerability has been uncovered in Meta’s Muse AI agent for macOS, potentially allowing threat actors to compromise the assistant, intercept user input, inject malicious instructions, and exfiltrate sensitive authentication data. This flaw is particularly concerning as a compromised Muse agent could inherit the broad system and service permissions already granted by the user.
Table Of Content
The discovery comes from security researcher Patrick Wardle, founder of Objective-See, who detailed the issue along with a proof-of-concept exploit named “not-a-mused.” Wardle’s investigation revealed that Muse exposes an undocumented configuration setting, endo_voyager_dictation_endpoint, which can be modified by any unprivileged local process without requiring elevated permissions. By altering this value, an attacker can redirect Muse’s dictation traffic away from its legitimate backend to a server under their control.
Once the dictation endpoint is rerouted, an attacker gains the ability to capture spoken audio and prompts before they reach Muse, manipulate the commands delivered to the agent, and steal authentication credentials associated with the victim’s account. This creates a direct pathway for prompt injection and session hijacking, enabling the execution of malicious commands or delivery of harmful content through a seemingly trusted AI workflow.
Meta’s Muse AI Agent: A High-Value Target
It is important to note that this vulnerability does not facilitate remote code execution on a pristine Mac. An attacker must first establish a local presence, typically through conventional malware or social engineering. However, Wardle emphasizes that the defect acts as a significant access amplification mechanism. Standard malware, usually constrained by macOS privacy controls, could exploit Muse’s pre-existing, broader authority across connected services, effectively escalating its own capabilities.
This exploit underscores the inherent danger when a low-privilege foothold can be weaponized against a trusted agent that possesses extensive delegated authority across numerous integrated services. Meta positions Muse as capable of interacting with files, applications, and browser tabs, connecting to email and calendars, browsing the web, facilitating purchases, and performing background tasks. While Muse is designed to request approval for sensitive actions and maintain an audit trail, an attacker controlling its trusted command channel could potentially bypass these safeguards and misuse connected resources.
Wardle’s proof of concept implements only a fraction of the more than 50 commands exposed by Muse. Further demonstrations have reportedly shown a compromised account identifying linked devices and instructing an online iPhone to report its location or initiate a Bluetooth Low Energy scan, indicating that the potential impact could extend beyond the infected Mac itself.
The disclosure has intensified ongoing discussions about the security implications of highly privileged AI agents, which could become attractive single points of failure for attackers. Wardle highlighted that traditional endpoint detection tools might struggle to differentiate between actions initiated by a legitimate user, the AI agent, or an attacker when commands are routed through a trusted, signed application. Reportedly, a former Meta AI security engineering manager has also expressed reluctance to use Muse due to security and privacy concerns.
Meta markets Muse as a secure personal agent, featuring a dedicated Secure VM, protected credential storage, and user-controlled permissions. The company also operates a public bug bounty program, offering significant rewards for qualifying Muse security flaws and impactful prompt-injection reports. At the time of initial reports, Meta had not publicly addressed Wardle’s specific findings.
What You Should Do
Until a verified fix is released by Meta, macOS users who utilize Muse AI should take immediate steps to mitigate potential risks:
- Pause or Disable Muse: Consider temporarily pausing or disabling the Muse application until a patch becomes available.
- Review and Revoke Permissions: Carefully review all permissions granted to Muse and revoke any unnecessary access to applications, files, or connected accounts.
- Rotate Credentials: If there is any suspicion of compromise, immediately rotate authentication credentials for any accounts linked to Muse.
- Monitor for Suspicious Activity: Remain vigilant for any unexpected or unauthorized activity originating from the Muse agent or related processes.
- Organizations: Restrict the use of unapproved AI agents on managed Macs and implement monitoring for any processes attempting to modify Muse’s endpoint configuration.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.