Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A zero-day vulnerability in Meta’s Muse AI agent for macOS could allow malware already running under a user account to hijack the assistant, intercept dictated prompts, inject malicious instructions, and steal authentication material.

The flaw is especially concerning because a compromised agent could inherit the extensive permissions and connected-service access that users have entrusted to Muse.

Security researcher Patrick Wardle, founder of Objective-See, disclosed the issue alongside a proof-of-concept exploit named “not-a-mused.” His research found that Muse exposes an undocumented configuration setting called endo_voyager_dictation_endpoint, which an unprivileged local process can modify without elevated permissions. Changing that value redirects Muse’s dictation traffic from its intended destination to an attacker-controlled server.

Once the endpoint is redirected, an attacker could capture dictated audio and prompts before they reach Muse’s backend, manipulate the instructions delivered to the agent, and obtain authentication data associated with the victim’s account. This creates a pathway for prompt injection and session hijacking, potentially enabling malicious commands or content to be delivered through a trusted AI workflow.

Meta’s Muse AI Agent 0-Day Vulnerability

The vulnerability does not provide remote code execution against a clean Mac. An attacker must first gain the ability to run code as the local user, perhaps through conventional malware or a social-engineering technique. However, Wardle argues that the defect acts as access amplification: ordinary malware constrained by macOS privacy controls could target Muse and exploit the broader authority already granted to the agent.

The exploit therefore highlights how a low-privilege foothold can become dangerous when a trusted agent holds expansive delegated authority across connected services.

That authority can be substantial. Meta says Muse can work with files, applications and browser tabs, connect to email and calendars, browse the web, make purchases and continue performing tasks in the background. It can also request approval for sensitive actions and maintain an audit trail, but an attacker who controls its trusted command channel may be positioned to misuse connected resources.

Wardle’s proof of concept implements only a subset of more than 50 commands exposed by Muse. Separate demonstrations reportedly showed the compromised account identifying linked devices and directing an online iPhone to return location information or initiate a Bluetooth Low Energy scan, extending the potential impact beyond the infected Mac.

The disclosure has intensified concerns about highly privileged AI agents becoming single points of failure. Wardle noted that endpoint detection tools may struggle to distinguish actions initiated by a user, the agent, or an attacker when commands are executed through a trusted, signed application. A former Meta AI security engineering manager also reportedly said he would not use Muse because of security and privacy concerns.

Meta markets Muse as a security-focused personal agent built around a dedicated Secure VM, protected credential storage and user-controlled permissions. The company also operates a public bug bounty offering rewards of up to $300,000 for qualifying Muse security flaws or impactful prompt-injection reports. Meta had not publicly responded to Wardle’s specific findings when initial reports appeared.

Until a verified fix is available, Mac users should treat Muse as a high-value security target. Users can reduce exposure by pausing the application, reviewing and revoking unnecessary permissions and connected accounts, rotating authentication credentials if compromise is suspected, and monitoring for unexpected agent activity. Organizations should also restrict unapproved AI agents on managed Macs and investigate any process that modifies Muse’s endpoint configuration.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware appeared first on Cyber Security News.