SlowMist Flags Zero-Day Vulnerability in Muse AI Assistant for Mac, Warning of User Data Risk
Key Takeaways
- •Local processes on the same Mac may reroute Muse prompts away from their intended destination.
- •The vulnerability could facilitate prompt injection and expose sensitive personal data, including financial records.
- •SlowMist classified the issue as a zero-day because it was disclosed before a fix was available.
- •Users should avoid installing untrusted Muse-related software while awaiting official mitigation guidance.
- •Muse’s developers have yet to provide a reported patch addressing the flaw.

Security researchers at SlowMist, a blockchain security firm, have disclosed a zero-day vulnerability in Muse, an AI assistant for Mac, warning that the flaw could allow unauthorized processes to hijack the assistant and place sensitive user data at significant risk. The alert was issued by the @SlowMist_Team account on X (original post here).
According to the disclosure, local processes running on the same machine can redirect prompts dictated by users to attacker-controlled endpoints rather than their intended destination. That mechanism creates conditions for prompt injection and unauthorized access to personal data, including financial records. In practical terms, the risk stems from processes already running on a user's Mac — which is why the researchers' interim guidance focuses on the software users choose to install.
Until a fix is implemented, SlowMist urges users to remain vigilant and to avoid installing untrusted Muse-related software.
How the Flaw Works
Muse is a voice-activated assistant built for Mac users, allowing them to complete tasks and retrieve data through dictated commands. The newly discovered zero-day turns this interaction model into an attack surface: a user's spoken prompts can be intercepted locally and rerouted to servers under an attacker's control.
The potential consequences are severe. Redirected prompts can be used to stage prompt-injection attacks — a technique in which manipulated inputs alter the behavior of an AI system — and could expose the personal information the assistant handles, with financial records among the categories of data at risk.
Context and User Guidance
The disclosure arrives amid a broader rise in cybersecurity threats affecting AI applications and serves as a reminder of the vulnerabilities that can exist in software used daily by millions. It also underscores the need for developers to prioritize security in applications that process sensitive personal information.
A zero-day designation refers to a security flaw disclosed before a fix is available, leaving users with little time to protect themselves. No immediate fix was available at the time of the alert and the researchers say urgent precautions are required in the interim. Users are advised to steer clear of untrusted Muse-related installations and to monitor official channels for advisories and mitigation strategies.
Among the developments to watch is whether Muse's developers ship a software patch addressing the flaw. Users are encouraged to stay informed about security updates and potential exploits as the situation develops, in order to safeguard data integrity.
This article is for informational purposes only and does not constitute financial advice.
Source: Coinfomania