A zero-day vulnerability in Muse, the hyped Meta AI Assistant, could allow locally run apps and terminal commands to gain complete control over the agent and perform malicious actions.
Despite Meta promising that Muse was a “widely available personal AI agent,” it released Muse only for macOS and Android, with no Windows counterpart.
Meta also lauds Muse as “built from the ground up for privacy and security.” The company claims that the AI agent runs on “Muse Secure VM” with its own resources, including a browser, storage, CPU, and memory. However, its design choices could enable attackers to escalate local privileges and perform malicious actions.
Meta AI assistant Muse zero-day vulnerability enables malware injection
Dubbed “not‑a‑mused,” the zero-day vulnerability in Meta’s AI assistant Muse could allow an attacker to exploit its privileges to perform malicious actions.
Meta says Muse can book appointments, handle customer service, fill forms, make purchases, and proactively take tasks off your plate. It can also accomplish other generic AI tasks, such as generating images and creating documents.
To complete these tasks, Muse can connect with other apps and services, including WhatsApp, email, calendar, and social media accounts. Additionally, Meta’s AI assistant can create custom apps on the fly to complete specific tasks for which no apps exist.
However, completing the tasks requires Muse to access user accounts and authenticate with various services, including highly restricted ones such as saving files to the device, location monitoring, and accessing the microphone and camera.
Additionally, it also exposes undocumented settings, which are internal configurations that are not exposed to the user interface. According to Patrick Wardle, the cybersecurity researcher who discovered the zero-day vulnerability, some of the permissions are quite harmless, such as controlling the dark theme.
However, they also include sensitive settings such as endo_voyager_dictation_endpoint, which determines where speech and dictation transcription occurs. While it usually points to a Meta-controlled endpoint, a logged-in malicious actor could change it to an attacker-controlled domain, intercept Muse dictation, and access the AI assistant’s authentication token.
They could then abuse Muse privileges to carry out various malicious actions without having to write custom code for each exploit. While Meta says the zero-day vulnerability was a local privilege escalation attack, malicious actors could use ClickFix techniques to trick users into executing commands like uploading sensitive data or writing malicious files to disk. According to Wardle, endpoint detection tools could struggle to block the malicious actions when executed by a trusted agent.
“In the proof of concept, an attacker went from compromising the Muse Agent, gaining access to all Muse data and capabilities including a linked iPhone,” said Alan Snyder, CEO of NowSecure. “That shows how agentic AI expands the security boundary beyond one application or device and how one app can be used to attack and exploit another app.”
However, the zero-day vulnerability affects only macOS, not Android, and there is no Windows version at the time of publication. Additionally, the macOS version was exploitable because the operating system stores the dictation setting under the app’s local preference, which any program running under the user’s account can modify. Subsequently, the dictation setting was not remotely exploitable.
Amazon blocks Meta AI assistant Muse
Amazon blocked Muse after the zero-day vulnerability was made public, claiming it violated the company’s Conditions of Use. With the AI assistant capable of shopping on the user’s behalf, Amazon’s concerns were not far-fetched.
Meanwhile, Meta has released security hotfixes for the zero-day vulnerability by removing the dictation setting in production builds.
“Meta moved quickly to patch this zero-day, but security teams should pay close attention to the access Muse had once the agent was compromised,” Snyder explained. “The first question every enterprise should ask is simple: What can this agent see, and what can it do? Security teams need to inventory the services, devices and credentials agents can access, including API keys that may not appear in traditional OAuth monitoring. Then they need to test those complete workflows, enforce least-privilege access, and make sure sensitive actions are visible and auditable. Ultimately, you cannot manage agentic AI if you cannot see its reach.”
Wardle tried to explain and criticize Meta’s design choices. He defended Meta’s use of remote dictation, which runs in the cloud, rather than macOS’s local dictation, which stays on the device, for logging purposes. However, using macOS’s default dictation was a far better option.
Wardle also criticized Meta’s decision to allow the AI assistant to control all undocumented settings, including the dictation endpoint. The Objective-See founder argued that, while Meta may have allowed Muse to tinker with all undocumented settings to control the user interface, it ultimately enabled the exploitation of the zero-day vulnerability.

