cd /news/ai-safety/a-zero-day-has-been-released-for-met… · home topics ai-safety article
[ARTICLE · art-136544] src=github.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

A zero-day has been released for Meta's Muse

A proof-of-concept zero-day exploit has been released for Meta's Muse app, abusing an undocumented setting called endo_voyager_dictation_endpoint that lets an unprivileged local process redirect Muse's dictation traffic to an attacker-controlled endpoint. According to the PoC's author, the local attack can capture dictated audio and prompts, enable prompt injection into Muse, steal Muse authentication material, and abuse whatever access the user has granted the app, since Muse may hold broader access than ordinary local malware. The PoC implements a subset of the 50+ commands exposed by Muse and is triggered by clicking the microphone button and dictating a prompt, and was provided for security research and educational purposes.

read1 min views1 publishedSep 22, 2026
A zero-day has been released for Meta's Muse
Image: Michielbdejong (auto-discovered)

A proof-of-concept for a local Muse (https://muse.ai) vulnerability 0day that can let an unprivileged local process redirect Muse’s dictation traffic and abuse the trust/access granted to the app.

Muse exposes an undocumented setting:

endo_voyager_dictation_endpoint

A local attacker or malware can modify this endpoint without special privileges.

Once redirected, dictated prompts can be sent to an attacker-controlled endpoint, potentially allowing:

  • Capture of dictated audio/prompts
  • Prompt injection into Muse
  • Theft of Muse authentication material
  • Abuse of whatever access the user has granted Muse

In short: Muse’s access can potentially become the attacker’s access.

Run:

./not-a-mused -h

for available options.

The PoC implements a subset of the 50+ commands exposed by Muse.

Once running, click the microphone button in Muse and dictate a prompt to trigger the PoC.

This is a local attack. An attacker must already be able to execute code as the local user.

The concern is that Muse may have significantly broader access than ordinary local malware, making it a particularly useful target for privilege/access amplification.

Provided for security research and educational purposes.

── more in #ai-safety 4 stories · sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-zero-day-has-been-…] indexed:0 read:1min 2026-09-22 ·