Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Teams Phishing Attacks Steal Windows Credentials
September 22, 2026
Critical 0-Day in Meta Muse AI Agent Lets Attackers Inject Malware
September 22, 2026
Google Fined €403M for GDPR Violations Over Location Data Tracking
September 21, 2026
Home/CyberSecurity News/Critical 0-Day in Meta Muse AI Agent Lets Attackers Inject Malware
CyberSecurity News

Critical 0-Day in Meta Muse AI Agent Lets Attackers Inject Malware

Key Takeaways A newly discovered zero-day vulnerability in Meta’s Muse AI agent for macOS allows local attackers to hijack the assistant. The flaw enables interception of user dictation, injection of...

David kimber
David kimber
September 22, 2026 3 Min Read
2 0

Key Takeaways

  • A newly discovered zero-day vulnerability in Meta’s Muse AI agent for macOS allows local attackers to hijack the assistant.
  • The flaw enables interception of user dictation, injection of malicious commands, and theft of authentication tokens.
  • While it requires initial local access, the vulnerability amplifies the capabilities of low-privilege malware by leveraging Muse’s extensive permissions.
  • No official patch is currently available from Meta, necessitating immediate user mitigation steps.

A critical zero-day vulnerability has been uncovered in Meta’s Muse AI agent for macOS, potentially allowing threat actors to compromise the assistant, intercept user input, inject malicious instructions, and exfiltrate sensitive authentication data. This flaw is particularly concerning as a compromised Muse agent could inherit the broad system and service permissions already granted by the user.

Table Of Content

  • Key Takeaways
  • Meta’s Muse AI Agent: A High-Value Target
  • What You Should Do

The discovery comes from security researcher Patrick Wardle, founder of Objective-See, who detailed the issue along with a proof-of-concept exploit named “not-a-mused.” Wardle’s investigation revealed that Muse exposes an undocumented configuration setting, endo_voyager_dictation_endpoint, which can be modified by any unprivileged local process without requiring elevated permissions. By altering this value, an attacker can redirect Muse’s dictation traffic away from its legitimate backend to a server under their control.

Once the dictation endpoint is rerouted, an attacker gains the ability to capture spoken audio and prompts before they reach Muse, manipulate the commands delivered to the agent, and steal authentication credentials associated with the victim’s account. This creates a direct pathway for prompt injection and session hijacking, enabling the execution of malicious commands or delivery of harmful content through a seemingly trusted AI workflow.

Meta’s Muse AI Agent: A High-Value Target

It is important to note that this vulnerability does not facilitate remote code execution on a pristine Mac. An attacker must first establish a local presence, typically through conventional malware or social engineering. However, Wardle emphasizes that the defect acts as a significant access amplification mechanism. Standard malware, usually constrained by macOS privacy controls, could exploit Muse’s pre-existing, broader authority across connected services, effectively escalating its own capabilities.

This exploit underscores the inherent danger when a low-privilege foothold can be weaponized against a trusted agent that possesses extensive delegated authority across numerous integrated services. Meta positions Muse as capable of interacting with files, applications, and browser tabs, connecting to email and calendars, browsing the web, facilitating purchases, and performing background tasks. While Muse is designed to request approval for sensitive actions and maintain an audit trail, an attacker controlling its trusted command channel could potentially bypass these safeguards and misuse connected resources.

Wardle’s proof of concept implements only a fraction of the more than 50 commands exposed by Muse. Further demonstrations have reportedly shown a compromised account identifying linked devices and instructing an online iPhone to report its location or initiate a Bluetooth Low Energy scan, indicating that the potential impact could extend beyond the infected Mac itself.

The disclosure has intensified ongoing discussions about the security implications of highly privileged AI agents, which could become attractive single points of failure for attackers. Wardle highlighted that traditional endpoint detection tools might struggle to differentiate between actions initiated by a legitimate user, the AI agent, or an attacker when commands are routed through a trusted, signed application. Reportedly, a former Meta AI security engineering manager has also expressed reluctance to use Muse due to security and privacy concerns.

Meta markets Muse as a secure personal agent, featuring a dedicated Secure VM, protected credential storage, and user-controlled permissions. The company also operates a public bug bounty program, offering significant rewards for qualifying Muse security flaws and impactful prompt-injection reports. At the time of initial reports, Meta had not publicly addressed Wardle’s specific findings.

What You Should Do

Until a verified fix is released by Meta, macOS users who utilize Muse AI should take immediate steps to mitigate potential risks:

  • Pause or Disable Muse: Consider temporarily pausing or disabling the Muse application until a patch becomes available.
  • Review and Revoke Permissions: Carefully review all permissions granted to Muse and revoke any unnecessary access to applications, files, or connected accounts.
  • Rotate Credentials: If there is any suspicion of compromise, immediately rotate authentication credentials for any accounts linked to Muse.
  • Monitor for Suspicious Activity: Remain vigilant for any unexpected or unauthorized activity originating from the Muse agent or related processes.
  • Organizations: Restrict the use of unapproved AI agents on managed Macs and implement monitoring for any processes attempting to modify Muse’s endpoint configuration.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareSecurityVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Google Fined €403M for GDPR Violations Over Location Data Tracking

Next Post

Microsoft Teams Phishing Attacks Steal Windows Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Entra ID to Block SMS First-Factor Sign-Ins Globally in February 2027
September 21, 2026
Payload Ransomware Abuses Group Policy to Disrupt Windows Domains
September 21, 2026
Malicious npm Package Hides Malware in Runtime Code
September 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us