A zero-day vulnerability in Meta’s Muse AI agent for macOS enables malware already running under a user account to hijack the assistant, intercept dictated prompts, inject malicious instructions, and steal authentication material. Security researcher Patrick Wardle, founder of Objective-See, disclosed the issue alongside a proof-of-concept exploit named “not-a-mused.” His research revealed that Muse exposes an undocumented configuration setting called endo_voyager_dictation_endpoint, which an unprivileged local process can modify without elevated permissions. Once the endpoint is redirected, an attacker can capture dictated audio and prompts before they reach Muse’s backend, manipulate the instructions delivered to the agent, and obtain authentication data associated with the victim’s account.
Meta states that Muse can interact with files, applications, and browser tabs, connect to email and calendars, browse the web, make purchases, and continue performing tasks in the background. Separate demonstrations reportedly showed the compromised account identifying linked devices and directing an online iPhone to return location information or initiate a Bluetooth Low Energy scan, extending the potential impact beyond the infected Mac. The company also offers a public bug bounty program, rewarding up to $300,000 for qualifying Muse security flaws or impactful prompt-injection reports.
Users can mitigate exposure by pausing the application, reviewing and revoking unnecessary permissions and connected accounts, rotating authentication credentials if suspicion of compromise is present, and monitoring for unexpected agent activity.











