Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware
A local zero-day in Meta's Muse agent lets existing malware redirect dictation, inject prompts, and steal credentials.
Patrick Wardle of Objective-See disclosed a macOS zero-day in Meta's Muse AI agent and released a proof of concept named not-a-mused. An unprivileged local process can change the undocumented endo_voyager_dictation_endpoint setting, redirecting dictation so an attacker can capture prompts, inject instructions, and obtain authentication data. The flaw does not remotely compromise a clean Mac; it amplifies malware already running as the user and could misuse Muse's access to files, mail, browsers, purchases, and linked devices. Meta had not publicly responded, while its bug bounty offers up to $300,000 for qualifying Muse flaws.