Meta’s new AI assistant Muse was found to contain a zero-day vulnerability that could let attackers use its connected apps—including WhatsApp, email, calendars, and social media accounts—to access sensitive information.
Exploiting the flaw is more complicated than installing ordinary malware. Muse must be integrated with other services, voice dictation must be enabled, and the attacker must already have local control of the Mac.
How “not-a-mused” works
Muse, currently available exclusively for Mac, is designed to book appointments, complete forms, handle customer service, make purchases, generate images, and create documents. Those capabilities require connections to services such as email, WhatsApp, calendars, and social media—the first condition for exploiting the vulnerability.
The second condition is voice dictation. Security researcher Patrick Wardle found that Muse mishandles commands received through voice, potentially allowing an attacker to redirect those commands and use the assistant’s privileges to reach connected apps and their contents.
Wardle named the vulnerability “not-a-mused.” It involves an undocumented setting called endo_voyager_dictation_endpoint, which determines where Muse sends dictation after a user speaks a command. The instruction is then processed in the cloud, where Meta may log it.
The third condition is local access. An attacker must be able to modify the endpoint setting, meaning the device has already been compromised through remote monitoring and management tools, low-level malware, or physical access.
On a compromised Mac with Muse connected to productivity apps, an attacker could redirect a user’s voice command through infrastructure they control. Muse would send its authentication tokens along with the instruction. If the attacker captures those tokens quickly, they can access the assistant and use it to retrieve sensitive information from connected services.
The vulnerability therefore combines privilege escalation with data exfiltration.
Proof of concept and unresolved risk
“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica.
He said attackers could use the AI assistant instead of developing comprehensive Mac malware designed to steal data. His proof-of-concept attacks could write malicious files to disk and take pictures, often without giving even a vigilant user an obvious warning.
Meta has been informed but has not yet commented or released a patch.
AI assistants are increasingly capable of completing complex tasks, including booking travel, managing meetings, and making purchases. To perform those actions, however, they require extensive permissions—raising concerns across the security community.
Researchers warn that AI agents can be manipulated or tricked. A hidden instruction in a phishing email, for example, could persuade an agent tasked with summarizing the message to exfiltrate PDF files from the victim’s inbox. Early agentic AI systems have also been known to cause accidental damage, including deleting email inboxes.
AI assistants are likely to remain a major part of computing, but their security and permission controls will need to mature before they can become mainstream.
Also Read
- Ancient School Linked to Aristotle and Alexander the Great Unearthed in Northern Greece
- Peloton Unveils the Foldable Tread Flex and Updated Tread Vision Models for Fall 2026
- A ‘Once-in-a-Century’ Impact: Scientists Discover the Freshest Lunar Crater Ever Recorded
- SUSE Offers Voluntary Separation to Long-Tenured Employees During Business Restructuring


