Meta Muse Zero-Day Turns AI Agent Privileges Into an Attack Surface
TL;DR
Security researcher Patrick Wardle disclosed a zero day vulnerability in Meta’s Muse macOS application that allowed an unprivileged local process to redirect Muse’s dictation traffic to an attacker controlled endpoint. The attack did not provide initial remote access: an attacker first needed the ability to execute code under the victim’s local user account. However, once that prerequisite was met, the flaw could be used to capture dictated prompts, inject instructions into Muse, steal Muse authentication material, and leverage permissions the user had already granted to the AI agent.
Wardle’s proof of concept, not a mused, exploited an undocumented setting named endo_voyager_dictation_endpoint. Because local processes could modify this setting without special privileges, Muse could be made to send dictation traffic to infrastructure controlled by an attacker instead of Meta. Wardle demonstrated follow on actions including writing malicious files and taking pictures through Muse. Ars Technica also reported an attack path in which a malicious proxy inserts instructions into a legitimate voice prompt while obtaining the Muse authentication token.
Meta subsequently issued a hot-fix. Meta characterized the issue as a local privilege escalation attack rather than a remote exploit, emphasizing that malicious code must already be executing under the user’s account.
What Happened
Meta launched Muse on September 8 as a personal AI agent capable of carrying out actions on behalf of users. Meta states that Muse can send emails, book travel, use connected services, browse websites, and perform other tasks, while operating within a dedicated secure VM and using safeguards around credentials and external actions.
Wardle subsequently identified a weakness in the macOS client. Muse exposed an undocumented configuration value:
endo_voyager_dictation_endpoint
According to Wardle's published PoC, any local process running as the user could modify this value without special privileges. When the user subsequently activated Muse's microphone and dictated a prompt, the traffic could be redirected to an attacker-controlled server.
The PoC identifies four resulting capabilities:
- capture dictated audio or prompts
- inject prompts into Muse
- steal Muse authentication material
- abuse access already granted by the user to Muse
The attack therefore does not compromise the Mac from the Internet by itself. Wardle explicitly states that the attacker must already have local code execution as the user. The security significance comes from what happens next: a relatively low-privileged local process can potentially inherit the considerably broader trust and capabilities assigned to the AI agent.
Core Attack Analysis
1. Local execution is the prerequisite
This vulnerability is not an initial access vulnerability. The attacker must first obtain the ability to execute code in the victim's user context. Wardle demonstrated that even an unprivileged process could perform the configuration change.
Ars Technica additionally described a ClickFix style scenario as one possible way such local execution could be obtained, but ClickFix is not required by the vulnerability itself.
2. A trusted AI communication path is redirected
The local process changes Muse's dictation endpoint from Meta infrastructure to attacker controlled infrastructure.
This creates a security boundary failure: Muse treats a locally configurable endpoint as part of a trusted instruction path even though unprivileged local software could modify it.
3. The attacker can modify instructions before Muse receives them
Ars reported a demonstrated architecture in which the malicious endpoint operates as a proxy between the Muse client and Meta. A user can issue a legitimate voice command, after which the proxy can append an attacker selected instruction before forwarding the request onward.
This is where the conventional software vulnerability crosses into an AI-native instruction-integrity problem: the agent can receive instructions that did not originate with the user while processing them within the user's trusted session.
4. Muse's existing privileges amplify the compromise
Muse requires access to resources and connected services in order to perform tasks for the user. Ars reports that Wardle's PoCs were able to use Muse to write malicious files and take pictures, sometimes without notifying the user.
The researcher's PoC describes the security consequence succinctly: Muse may possess significantly broader access than the local malware itself, making the agent useful for privilege/access amplification.
5. Authentication material extends the impact
The redirected flow could expose Muse authentication material. Ars reports that possession of the token could give an attacker control of the Muse account, and describes the token as enabling continued control after the initial interception.
This distinction matters: the vulnerability does not merely manipulate one model response. It can potentially convert temporary local code execution into control over the user's authenticated agent session.
The Attack Progression Across The AI Kill Chain
1. Reconnaissance — Bypassed entirely. The source doesn't disclose a reconnaissance stage. The attack begins after the attacker already has local code execution under the victim's user account, which Wardle identifies as a prerequisite. Ars Technica describes a ClickFix-style scenario as one possible route to that foothold, but the vulnerability itself doesn't depend on any specific access method.
2. Trust Establishment & Manipulation — Bypassed entirely. The source doesn't disclose a trust-building stage, and the attack doesn't need one. Muse exposed an undocumented setting, endo_voyager_dictation_endpoint, that any local process running as the user could change without special privileges. The attacker never has to earn Muse's trust, because the configuration that defines its trusted channel was already open to unprivileged software.
3. Instruction / Input Weaponization — Active. The attacker changes Muse's dictation endpoint from Meta's infrastructure to one the attacker controls. When the user turns on Muse's microphone and dictates a prompt, the traffic goes to the attacker's server first. In the architecture Ars reported, that server acts as a proxy between the Muse client and Meta, and it can append an attacker-chosen instruction to the user's legitimate voice command before passing the request along.
4. Reasoning-Time Execution — Active. Muse receives the altered request inside the user's trusted session and has no way of telling the user's words apart from the attacker's additions. It acts on the injected objective along with, or in place of, the user's original request. This is where a conventional software flaw becomes an AI-native instruction-integrity problem: the agent follows instructions that never came from the user.
5. Tool Invocation — Active. Muse needs access to resources and connected services to do its job, and the injected instructions can put that access to work. Wardle's PoCs used Muse to write malicious files and take pictures, sometimes without notifying the user. The agent's legitimate capabilities become the attacker's toolkit.
6. Privilege Escalation — Active. The local process starts with limited privileges but can take on the much broader access the user already granted to Muse. The redirected flow also exposes Muse's authentication material. As Wardle's PoC puts it, Muse may have significantly broader access than the local malware itself, which makes the agent a tool for amplifying privilege and access.
7. Lateral Movement — Bypassed entirely. The source doesn't disclose lateral movement. The reported impact stays within what Muse itself can reach through the permissions the user has granted it.
8. Persistence — Active. Stolen Muse authentication material gives the attacker a foothold that outlasts a single intercepted prompt. Ars reports that possessing the token could give an attacker control of the Muse account and allow continued control after the initial interception. That turns temporary local code execution into lasting control of the user's authenticated agent session.
9. AI-Native C2 — Active. The attacker's command channel is Muse's own trusted dictation path. With that destination rebound to attacker infrastructure, the attacker sits inside the communication meant for Muse and can intercept and modify it. No separate command channel is needed, because the agent's trusted instruction path already serves that role.
10. Action on Objectives — Active. The compromised agent uses its legitimate permissions to access or act on user resources. Ars describes an example involving exfiltration of WhatsApp messages, and Wardle demonstrated camera and file actions. None of these required the attacker to break into those resources directly, because Muse was already authorized to reach them.

Mitigation Strategy
Patch the vulnerable client
Meta says it issued a hot-fix for the Muse Mac application after disclosure. Updating the client is therefore the direct remediation for the disclosed vulnerability.
Protect agent control plane configuration
Security sensitive agent configuration, including inference endpoints, transcription endpoints, MCP servers, tool endpoints, proxy settings, and credential brokers, should not be modifiable by arbitrary local processes.
Changes to those values should require an appropriately privileged and authenticated administrative path.
Restrict agent network destinations
An agent URL allowlist could provide a second containment layer. If Muse were permitted to send transcription or agent traffic only to explicitly authorized Meta endpoints, changing the local configuration to an arbitrary attacker-controlled domain would not be sufficient to establish the malicious proxy.
This is particularly applicable to the Lineaje policy: AI agents may communicate only with destinations present in the approved URL allowlist.
For this incident, enforcement must occur outside the compromised agent/configuration itself, for example at an independent runtime policy, proxy, or network control layer.
Apply least privilege to AI agents
Agents should not automatically inherit a superset of the user's privileges merely because those permissions improve convenience.
Access to camera, microphone, files, email, messaging, location, credentials, and other sensitive resources should be separately scoped and revocable. Meta itself states that Muse lets users determine which applications it can access and what access it receives.
Require authorization for consequential actions
Sensitive operations should be independently authorized at execution time, particularly when an agent:
- accesses sensitive local data
- performs a delete operation
- uses cameras or microphones
- sends or exports data
- writes executable or script content
- accesses credentials
- acts across connected services
An approval layer should validate the requested action, rather than merely trusting that the request came through the agent.
Constrain tool invocation
A tool allowlist provides another containment control. Even if the agent's reasoning or instruction stream is compromised, it should only be able to invoke explicitly approved capabilities.
This maps directly to your existing tool allowlist policy. It would not by itself prevent the endpoint hijack, but could limit what the compromised Muse instance could subsequently do.
Detect privilege amplification through AI agents
Endpoint defenses should treat highly privileged AI agents as security-sensitive applications. Relevant telemetry includes:
- changes to agent endpoint/configuration settings;
- unexpected local processes modifying agent preferences;
- connections from agent processes to previously unseen domains;
- unusual camera, microphone, file, or credential access;
- unexpected tool execution initiated by the agent; and
- use of agent authentication tokens outside their expected execution context.
UnifAI Policy
UnifAI limits AI agents to approved tools and approved destinations, so a hijacked instruction channel can't quietly route prompts to an attacker or reach capabilities it was never meant to have. It also requires a human to approve risky operations like writing files, using the camera, or exporting data, so an injected instruction can't turn an agent's permissions against the user without someone signing off.
AI_IAC_015, AI_IAC_020, AI_APP_SEC_068, AI_APP_SEC_069
Lessons / Conclusion
The Muse vulnerability demonstrates an emerging characteristic of privileged AI agents: the agent itself becomes a privilege boundary.
The initial attacker in this case did not gain remote access through Muse. Instead, existing local code execution could potentially be amplified through the authority already delegated to the AI agent. An application that can access files, cameras, messaging accounts, calendars, and external services creates a high value target because compromising the agent can be more powerful than compromising an ordinary application.
It also shows why protecting the LLM alone is insufficient. The failure occurred in the infrastructure surrounding the model: a mutable endpoint controlling a trusted instruction channel. Once that trust anchor was redirected, attacker-controlled instructions could enter the agent workflow and legitimate agent permissions could be turned against the user.
For agentic systems, instruction integrity, configuration integrity, credential isolation, network destination control, and least privilege tool execution must therefore be treated as parts of the same security boundary.
Meta's hot-fix addressed the disclosed Muse flaw, but the architectural lesson is broader: an agent's authority should never automatically become the authority of whatever process can influence the agent.