{"slug": "a-zero-day-has-been-released-for-meta-s-muse", "title": "A zero-day has been released for Meta's Muse", "summary": "A proof-of-concept zero-day exploit has been released for Meta's Muse app, abusing an undocumented setting called endo_voyager_dictation_endpoint that lets an unprivileged local process redirect Muse's dictation traffic to an attacker-controlled endpoint. According to the PoC's author, the local attack can capture dictated audio and prompts, enable prompt injection into Muse, steal Muse authentication material, and abuse whatever access the user has granted the app, since Muse may hold broader access than ordinary local malware. The PoC implements a subset of the 50+ commands exposed by Muse and is triggered by clicking the microphone button and dictating a prompt, and was provided for security research and educational purposes.", "body_md": "A proof-of-concept for a local Muse ([https://muse.ai](https://muse.ai)) vulnerability 0day that can let an unprivileged local process redirect Muse’s dictation traffic and abuse the trust/access granted to the app.\n\nMuse exposes an undocumented setting:\n\n`endo_voyager_dictation_endpoint`\n\nA local attacker or malware can modify this endpoint without special privileges.\n\nOnce redirected, dictated prompts can be sent to an attacker-controlled endpoint, potentially allowing:\n\n- Capture of dictated audio/prompts\n- Prompt injection into Muse\n- Theft of Muse authentication material\n- Abuse of whatever access the user has granted Muse\n\nIn short: Muse’s access can potentially become the attacker’s access.\n\nRun:\n\n```\n./not-a-mused -h\n```\n\nfor available options.\n\nThe PoC implements a subset of the 50+ commands exposed by Muse.\n\nOnce running, click the microphone button in Muse and dictate a prompt to trigger the PoC.\n\nThis is a **local attack**. An attacker must already be able to execute code as the local user.\n\nThe concern is that Muse may have significantly broader access than ordinary local malware, making it a particularly useful target for privilege/access amplification.\n\nProvided for security research and educational purposes.", "url": "https://wpnews.pro/news/a-zero-day-has-been-released-for-meta-s-muse", "canonical_source": "https://github.com/pwardle/not-a-mused", "published_at": "2026-09-22 01:45:55+00:00", "updated_at": "2026-09-22 02:23:38.428316+00:00", "lang": "en", "topics": ["ai-safety", "ai-products", "artificial-intelligence"], "entities": ["Meta", "Muse", "endo_voyager_dictation_endpoint", "not-a-mused"], "alternates": {"html": "https://wpnews.pro/news/a-zero-day-has-been-released-for-meta-s-muse", "markdown": "https://wpnews.pro/news/a-zero-day-has-been-released-for-meta-s-muse.md", "text": "https://wpnews.pro/news/a-zero-day-has-been-released-for-meta-s-muse.txt", "jsonld": "https://wpnews.pro/news/a-zero-day-has-been-released-for-meta-s-muse.jsonld"}}