• Meta Muse already has a majorly worrying zero-day security issue

    From TechnologyDaily@1337:1/100 to All on Tuesday, September 22, 2026 14:15:20
    Meta Muse already has a majorly worrying zero-day security issue

    Date:
    Tue, 22 Sep 2026 13:05:00 +0000

    Description:
    Crooks can reportedly take over Meta sessions and use them to exfiltrate data.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researcher Patrick Wardle finds zeroday in Metas new Muse AI assistant, Dubbed notamused, the exploit
    requires local compromise, voice dictation, and app integrations; attackers can hijack tokens and exfiltrate data Meta has been informed but no patch
    yet; flaw highlights risks of AI assistants with broad permissions Metas new Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that allowed attackers to gain access to peoples apps, such as WhatsApp or email.

    However, its not as straightforward as your usual zero-day - to exploit it, simply deploying malware will not suffice. Certain features need to be enabled, and certain integrations established before the bug could be leveraged. Not-a-mused A little background, for context: Meta recently released Muse, describing it as an assistant that can book appointments, fill out forms, and handle customer service. It says the tool, available exclusively for the Mac ecosystem for now, proactively takes tasks off your plate and makes purchases, generates images, and creates documents. Latest Videos From TechRadar Watch full video here:

    To do that, however, it needs to connect to apps such as email, WhatsApp, calendar, or social media accounts - and this connection is the first prerequisite needed to exploit the flaw.

    The second prerequisite is voice dictation. The vulnerability was found in
    the way Muse handles commands received via voice, meaning the attacker must piggyback onto voice commands in order to escalate privileges and access
    other apps and their content. You may like Mark Zuckerberg's Muse personal AI agent is a work accessory designed by people who don't do real work A dangerous Zoom screen-sharing bug could have let hackers hijack other devices on a call Metas new AI agent demands serious trust

    Now for the flaw itself. It was discovered by security researcher Patrick Wardle, founder of nonprofit Objective-See. He named it not-a-mused and says it hides in an undocumented setting called endo_voyager_dictation_endpoint. When a user narrates a voice command, that instruction is sent and processed in the cloud, where Meta can log it. This setting allows the user to change which endpoint receives the dictation.

    Which brings us to the third prerequisite. The threat actor must have local access to be able to change this setting in the first place. In other words, the device must already be compromised in some way, either via remote monitoring and management tools, or via low-level malware (or with physical access). Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    For the sake of the report, lets say that a theoretical user checks all the right boxes - theyre running a compromised machine and are talking to Muse thats already connected to other productivity apps. Instead of reaching Metas endpoints, the voice commands are first sent to attacker-controlled infrastructure, where the AI assistant, together with the instructions, also sends authentication tokens for the tool.

    If the attacker reacts fast enough, they can grab the token and access their targets AI tool. If its connected to other apps, such as WhatsApp or
    calendar, they can simply prompt it to extract whatever sensitive information is found inside.

    Not-a-mused is therefore a combination of data exfiltration and privilege escalation. What to read next A worrying ChatGPT bug let strangers read Gmail messages via a hidden cross-account channel Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers Claude Cowork
    can break its bonds and access Mac files, experts claim Ironing out the kinks We can manipulate the agent and leverage its privileges to do whatever we want, Wardle told Ars Technica .

    So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself. Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user.

    Meta has been informed, but is yet to comment, or issue a patch.

    AI assistants are all the rage nowadays. Theyve turned elaborate answer machines into tools that can complete assignments, even more complex ones. They can book flights and restaurant tables, make purchases, schedule and reschedule calls and meetings, and more. However, to do that, these tools
    need extensive permissions - something the security community is warning of.

    While theyre not openly speaking against it, they are advising caution. There are many stories of AI agents either going rogue, or simply being tricked by malicious actors. For example, a hidden prompt in a phishing email can trick an AI agent tasked with summarizing the message into exfiltrating all .PDF documents from the victims inbox.

    In the early days of agentic AI, there were reports of assistants simply deleting peoples inboxes.

    Assistants are likely here to stay, but there are still quite a few kinks to iron before they can hit the mainstream. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/meta-muse-already-has-a-majorly-worryin g-zero-day-security-issue


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)