Zero-Day Flaw in Meta's Muse AI Exposes Users to Extensive Security Risks
October 2, 2026
A zero-day vulnerability in Meta's Muse AI assistant could let attackers with local access take control of the agent and perform malicious actions by abusing its elevated privileges.
The flaw, dubbed not-a-mused, exploits undocumented permissions in Muse, including an endo_voyager_dictation_endpoint that could allow interception of dictation data and access to the AI's authentication token.
Muse runs on macOS and Android as a dedicated app with its own secure VM, a design that could nevertheless be leveraged to escalate privileges on the host system.
A proof-of-concept showed that compromising Muse could grant access to all Muse data and even a linked iPhone, illustrating how one compromised app can threaten multiple connected devices and apps.
Amazon blocked Muse citing a violation of its Terms of Use amid concerns over automated purchasing capabilities and potential misuse.
The issue primarily affects macOS; Android is not affected at publication, and there is no Windows version of Muse yet.
Meta released a security hotfix in production, removing the problematic dictation setting to address the immediate vulnerability, while researchers emphasized the need for broader visibility and least-privilege access for agentic AI.
Experts advise security teams to inventory agent reach, enforce least-privilege access, and ensure comprehensive visibility and auditing of agent actions to manage risks posed by agentic AI.
Attack scenarios could involve using agentic AI to access user accounts, save files, monitor location, and interact with connected apps and services like WhatsApp, email, calendar, and social media, potentially enabling broad compromises without creating new exploits for each target.
Summary based on 1 source
Get a daily email with more Tech stories
Source

CPO Magazine • Oct 2, 2026
Meta Muse AI Assistant’s Zero-Day Vulnerability Could Enable Attackers to Inject Malware