Security Researcher Discovers Zero-Day Vulnerability in Meta Muse AI Assistant

Wardle released a proof-of-concept exploit called “not-a-mused” on GitHub, and the vulnerability had not been assigned a CVE number in the reports.
The flaw could enable prompt injection and session hijacking by allowing an attacker to intercept dictated audio and prompts before they reach Muse’s backend, potentially compromising the assistant’s authentication credentials.
Meta markets Muse as security-focused, citing a dedicated Secure VM, protected credential storage, automated protections and user-controlled permissions; the company also operates a public bug bounty offering up to $300,000 for qualifying Muse vulnerabilities.
Muse had quickly become a major consumer hit, reaching the top of Apple’s U.S. App Store and surpassing ChatGPT, despite having launched only a few weeks earlier.
The incident highlights the tension between Muse’s convenience and its extensive functionality: the assistant can book appointments, fill out forms, handle customer service, browse the web and make purchases across linked services.
Meta's Muse AI assistant for macOS has a critical security flaw that lets malware already running on a user's Mac hijack the app and turn it into a backdoor. Malwarebytes reported that security researcher Patrick Wardle discovered the zero-day vulnerability, which allows attackers to redirect Muse's voice-dictation traffic to an attacker-controlled server. The flaw exposes audio, prompts, authentication tokens, and session data without requiring administrator privileges to exploit.
The vulnerability does not enable remote takeover of an uncompromised Mac—an attacker must first run code locally, often through malware or social engineering. But Muse's broad permissions to access calendars, email, files, cameras, microphones, and online services magnify the damage. Tech Insider noted that Meta left the flaw unpatched for at least 24 hours after disclosure, despite marketing Muse as security-focused and offering up to $300,000 for qualifying bug bounties.
Wardle's proof-of-concept exploit, called "not-a-mused," modifies an undocumented Muse setting that controls where voice-dictation traffic flows. An attacker with local code execution can redirect the audio stream to their own server before it reaches Meta's backend. This allows the attacker to intercept spoken commands, capture Muse's authentication tokens, and hijack the user's session. TechNadu noted that the vulnerability turns Muse into "the ultimate backdoor" for malware with limited privileges.
Once a malware operator controls the audio pipeline, they can inject fake prompts or commands that Muse will execute. Since Muse already has permission to write files, take photos, book appointments, and control linked services, the attacker inherits all those powers. The flaw amplifies what a piece of malware can do—a key reason security researchers flag it as particularly dangerous.
Muse launched only weeks ago but quickly climbed to the top of Apple's U.S. App Store, surpassing ChatGPT. Newsable and Khel Ja reported that analyst Ben Thompson said Muse poses a larger competitive threat to OpenAI and Anthropic than expected, because its agent capabilities let it perform real-world actions across many services. That convenience also makes it a lucrative attack surface for malware writers.
The app can handle customer service, book appointments, fill forms, browse the web, and make purchases through connected accounts. Each permission granted to Muse becomes a tool for an attacker to abuse. Muse's explosive popularity means malware authors have strong incentive to compromise it.
Meta positions Muse as a privacy-conscious and security-hardened assistant. The company cites features like a dedicated Secure VM, protected credential storage, automated threat defenses, and user-controlled permissions. It also runs a public bug bounty program offering up to $300,000 for valid Muse security reports. Yet the zero-day sat unpatched in released code, suggesting Meta's security architecture has gaps or the disclosure process moved slowly.
The vulnerability highlights a core tension in AI assistants: the more features and integrations they gain, the higher the risk if those features fall into malicious hands. Muse's design—built to seamlessly handle sensitive tasks across email, photos, payments, and personal calendars—makes it both powerful and dangerous if compromised.
Publishers
49
Articles
161
Reach
210