HeadlinesBriefing favicon HeadlinesBriefing.com

Meta Muse AI Agent Exploited via 0-Day Vulnerability

9to5Mac •
×

Meta has spent the last two weeks promoting the security of its new Muse personal AI agent, highlighting its dedicated Secure VM, Sentinel monitoring system, and bug bounty rewards up to $300,000. Mark Zuckerberg publicly stated the agent is “built from the ground up for privacy and security.” However, Patrick Wardle, macOS security researcher and friend of Security Bite, discovered a 0-day vulnerability in the Muse app on Mac. The flaw allows any local app or Terminal command to alter undocumented Muse settings without special macOS permissions.

One setting, endo_voyager_dictation_endpoint, controls where dictated prompts are sent. An attacker can redirect this to their own server, intercepting user prompts and potentially stealing tokens. Wardle named the finding “not-a-musing” in a GitHub repository.

The vulnerability undermines Meta’s security claims despite its extensive safeguards. Muse, launched earlier this month, is designed to perform tasks across apps and accounts but requires broad access, increasing risk. The issue was reported via 9to5Mac’s Security Bite segment, sponsored by Mosyle, the Apple Unified Platform trusted by over 45,000 organizations.