A Muse zero-day vulnerability has been identified in the Muse AI assistant for Mac, according to @SlowMist_Team. The flaw allows unauthorized local processes to hijack the assistant and redirect dictated prompts to attacker-controlled endpoints, creating significant risks to sensitive user data. Users are urged to avoid untrusted Muse-related installations until a fix is implemented.
Muse zero-day: how the flaw works
The vulnerability enables local processes to take control of the assistant’s workflow and route dictated prompts away from intended endpoints. That redirection can enable prompt injection and unauthorized access to personal information, including financial records, as described in the alert.
Scope and implications
Muse is an AI assistant designed for Mac users to perform voice-activated tasks and retrieve data. The newly disclosed zero-day highlights the potential for everyday software to expose sensitive information when exploited. With no immediate fix on the horizon, the issue raises wider concerns about security practices in AI applications and the need for developers to prioritize protections for tools that handle personal data.
What users should do
Until Muse developers release a patch, users are advised to avoid installing untrusted Muse-related software and to monitor official channels for advisories and mitigation guidance. Observers should also watch for software updates from Muse and any market reactions tied to the vulnerability.
This article is for informational purposes only and does not constitute financial advice.

