macOS security researcher Patrick Wardle said a serious zero-day vulnerability, a flaw without a released fix, in Muse, a personal AI agent that manages your Mac, lets local malware or an attacker invisibly hijack the agent.

Wardle said the endo_voyager_dictation_endpoint setting in Muse can be redirected locally without special privileges. After the user clicks the microphone and dictates a prompt, Muse sends the prompt to the attacker’s endpoint.

Wardle said the vulnerability can steal an authentication token and invisibly control Muse directly. He said a local attacker then gets access to the messages, email, and finances to which the user gave Muse access.

Claim check:

  • macOS security researcher Patrick Wardle said a serious zero-day vulnerability in Muse lets local malware or an attacker invisibly hijack the agent. (confirmed by the primary source: evidence; «But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.»)
  • Wardle said the endo_voyager_dictation_endpoint setting in Muse can be redirected locally without special privileges. (confirmed by the primary source: evidence; «Muse has an undocumented setting: endo_voyager_dictation_endpoint …that can be redirected locally with no special privileges!»)
  • Wardle said that after the user clicks the microphone and dictates a prompt, Muse sends the prompt to the attacker’s endpoint. (confirmed by the primary source: evidence; «So when you click 🎙️ and dictate a prompt, Muse sends it to the attacker’s endpoint instead 🤦‍♂️»)
  • Wardle said the vulnerability can steal an authentication token and invisibly control Muse directly. (confirmed by the primary source: evidence; «🔑 Steal your auth token & invisibly control Muse directly»)
  • Wardle said a local attacker gets access to the messages, email, and finances to which the user gave Muse access. (confirmed by the primary source: evidence; «Anything you gave Muse access to? Now the (local) attacker has it too: msgs, emails, finances… 💀»)

Publications:

Primary sources:

score 62.8 out of 100 · kind: incident · update 2