Muse: Muse AI Agent 0-Day Lets Local Malware Hijack Prompts and Steal Authentication Tokens

Muse: Muse AI Agent 0-Day Lets Local Malware Hijack Prompts and Steal Authentication Tokens

New Zero-Day Vulnerability in Muse AI Assistant Exposes Dictation Traffic and Authentication Risks

Security researcher Patrick Wardle has disclosed a proof-of-concept (PoC) for an alleged zero-day vulnerability in Muse, an AI assistant application, which could allow malware to intercept and manipulate dictation traffic. The flaw, documented in Wardle’s "not-a-mused" repository, exploits an undocumented configuration setting endo_voyager_dictation_endpoint that an unprivileged local process can modify.

By altering this setting, an attacker with prior local code execution (e.g., via malware or a trojanized application) could redirect Muse’s dictation traffic to an attacker-controlled server. The PoC demonstrates how dictated content, prompts, and even authentication material could be captured or manipulated when a user activates the microphone. Additionally, the attack could inject malicious prompts, potentially tricking the AI into misusing its existing permissions such as accessing sensitive accounts, APIs, or enterprise services.

While the vulnerability does not enable remote or unauthenticated exploitation, it amplifies risks for systems where Muse has elevated permissions. Compromised tokens or session data could allow attackers to impersonate users within Muse’s authorized scope. The PoC reportedly leverages a subset of over 50 commands exposed by the application, highlighting the broader security challenges of AI assistants operating with delegated access.

Organizations are advised to audit Muse’s permissions, monitor for unauthorized configuration changes, and restrict sensitive dictation until a vendor patch is released. The discovery underscores the growing threat of local attacks targeting trusted AI clients to exploit their integrated access.

Source: https://cyberpress.org/muse-ai-agent-0-day/

Muse TPRM report: https://www.rankiteo.com/company/amuse-concept-events

"id": "amu1790058459",
"linkid": "amuse-concept-events",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Artificial Intelligence / Technology',
                        'name': 'Muse AI Assistant',
                        'type': 'Software Application'}],
 'attack_vector': 'Local Code Execution',
 'data_breach': {'data_exfiltration': 'Possible (if redirected to '
                                      'attacker-controlled server)',
                 'personally_identifiable_information': 'Possible (if dictated '
                                                        'content includes PII)',
                 'sensitivity_of_data': 'High (authentication material, '
                                        'session data)',
                 'type_of_data_compromised': ['Dictated content',
                                              'Prompts',
                                              'Authentication material',
                                              'Session data',
                                              'Tokens']},
 'description': 'Security researcher Patrick Wardle disclosed a '
                'proof-of-concept (PoC) for an alleged zero-day vulnerability '
                'in Muse, an AI assistant application, which could allow '
                'malware to intercept and manipulate dictation traffic. The '
                'flaw exploits an undocumented configuration setting '
                "'endo_voyager_dictation_endpoint' that an unprivileged local "
                'process can modify. This could redirect Muse’s dictation '
                'traffic to an attacker-controlled server, capturing or '
                'manipulating dictated content, prompts, and authentication '
                'material. The attack could also inject malicious prompts, '
                'potentially tricking the AI into misusing its permissions to '
                'access sensitive accounts, APIs, or enterprise services.',
 'impact': {'data_compromised': 'Dictated content, prompts, authentication '
                                'material, session data, tokens',
            'identity_theft_risk': 'High (if authentication material is '
                                   'compromised)',
            'operational_impact': 'Potential misuse of AI permissions to '
                                  'access sensitive accounts, APIs, or '
                                  'enterprise services',
            'systems_affected': 'Muse AI Assistant application'},
 'lessons_learned': 'The discovery underscores the growing threat of local '
                    'attacks targeting trusted AI clients to exploit their '
                    'integrated access. Organizations should audit permissions '
                    'and restrict sensitive dictation until patches are '
                    'available.',
 'post_incident_analysis': {'corrective_actions': 'Vendor patch to secure the '
                                                  'configuration setting, '
                                                  'restrict permissions for AI '
                                                  'assistants with delegated '
                                                  'access',
                            'root_causes': 'Undocumented configuration setting '
                                           "'endo_voyager_dictation_endpoint' "
                                           'allowing unprivileged local '
                                           'modification'},
 'recommendations': ['Audit Muse’s permissions',
                     'Monitor for unauthorized configuration changes',
                     'Restrict sensitive dictation until a vendor patch is '
                     'released'],
 'references': [{'source': "Patrick Wardle's 'not-a-mused' repository"}],
 'response': {'containment_measures': 'Audit Muse’s permissions, monitor for '
                                      'unauthorized configuration changes, '
                                      'restrict sensitive dictation until a '
                                      'vendor patch is released',
              'enhanced_monitoring': 'Monitor for unauthorized configuration '
                                     'changes'},
 'title': 'Zero-Day Vulnerability in Muse AI Assistant Exposes Dictation '
          'Traffic and Authentication Risks',
 'type': 'Zero-Day Vulnerability',
 'vulnerability_exploited': 'Undocumented configuration setting '
                            "'endo_voyager_dictation_endpoint'"}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.