SlowMist|Sep 22, 2026 03:05
🚨 SlowMist TI Alert: Muse Zero-Day 🚨
According to a disclosure by @patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting.
⚠️ The flaw can redirect dictated prompts to an attacker-controlled endpoint, potentially enabling:
🎙️ Prompt/audio capture
💉 Prompt injection
🔑 Theft of authentication material
📱 Remote tasking of the user's connected mobile devices
Since Muse can access user-authorized data such as messages, emails, and financial information, a successful attack could potentially expose sensitive information accessible to the assistant.
🛡️ Users should avoid installing or running untrusted Muse-related PoCs and monitor for suspicious local activity until mitigations are available.
🔎 One of 0day PoCs: https://github.com/pwardle/not-a-mused
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink