A zero-day vulnerability dubbed not-a-mused in Meta's Muse AI application for macOS lets any unprivileged process already running on a device modify undocumented Muse settings, including endo_voyager_dictation_endpoint. Malware can redirect dictated audio and AI prompt traffic to an attacker-controlled transcription endpoint, exposing sensitive voice data and enabling prompt injection.
The redirected requests can also disclose a token that authenticates the victim's Muse account, allowing an attacker to take complete control of it. Researchers warn that Muse's broad user-granted permissions can let local malware effectively bypass macOS permission separation and abuse access available to the assistant; Meta had not responded publicly, while Amazon reportedly began blocking Muse from its website.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Amazon reportedly began blocking Meta's Muse AI assistant from its website on Sunday.
Researcher Patrick Wardle disclosed a proof of concept, dubbed not-a-mused, showing that any locally executing unprivileged process can modify Muse's undocumented endo_voyager_dictation_endpoint setting and redirect dictation traffic to an attacker-controlled endpoint. The redirected traffic can expose dictated audio and prompts and capture a Muse authentication token, potentially giving an attacker control of the victim's Muse account and access to permissions granted to the application.
Meta introduced its Muse AI assistant for macOS several weeks before the report. The assistant can connect to user services and may be granted broad permissions, including access to files, microphone, camera, location, and calendars.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.