🚨 META MUSE ZERO-DAY LETS LOCAL MALWARE HIJACK THE AI AGENT’S TRUST AND ACCESS
macOS security researcher Patrick Wardle has released a public PoC for not-a-mused, a local zero-day affecting Meta’s Muse AI assistant for macOS.
• Muse exposes an undocumented setting, endo_voyager_dictation_endpoint
• An unprivileged local process can modify the endpoint without administrator privileges
• Redirecting it can send dictated prompts to an attacker-controlled server
• Wardle’s PoC shows potential capture of prompts, prompt injection, theft of Muse authentication material and abuse of access already granted to the agent
• The attack requires existing local code execution — this is NOT a remote zero-click compromise
• The security impact is amplified because an AI agent may hold substantially broader permissions than the malware that initially lands on the Mac
• The researcher’s PoC implements a subset of more than 50 commands exposed by Muse
• No confirmed in-the-wild exploitation has been identified
• No public CVE or confirmed patched version was identified at the time of disclosure
⚠️ Analyst Note:
This is a strong example of AI agents becoming privilege amplifiers.
Traditional macOS controls may prevent ordinary malware from directly accessing sensitive resources, but if that malware can hijack a highly privileged agent already trusted by the user, the agent itself can become the attacker’s bridge into files, services and other authorized capabilities.
Original researcher PoC:
github.com/pwardle/not-a-mus…
#Meta #Muse #AISecurity #AgenticAI #macOS #ZeroDay #ThreatIntel #CyberSecurity #DDW #DarkWeb