{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0439",
  "aliases": [],
  "published": "2026-09-22T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Meta Muse on macOS, during normal assistant use, let local malware redirect dictation and capture the Muse token to read chat history and control the assistant.",
  "details": "## What\n\nThe Hacker News reported a macOS Muse flaw in an undocumented dictation setting. Malware already running as the logged-in user could redirect dictated text, add instructions Muse would trust and capture a token that accesses the user's Muse account and chat history.\n\n## Detection\n\nThe report describes a researcher proof of concept and says Meta later pointed to a fix whose operation was not independently confirmed.\n\n## Fix\n\nInstall Meta's latest Muse update and avoid granting the app more access than needed.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "meta-muse"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ARTICLE",
      "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "config-file-injection",
        "credential-exposure",
        "data-exfiltration"
      ],
      "cwe": [
        "CWE-15",
        "CWE-522"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI03",
          "ASI01"
        ],
        "atlas": [
          "AML.T0081",
          "AML.T0091.000"
        ]
      },
      "cveBoundary": "insecure-default",
      "noCveReason": "No CVE was assigned in the public disclosure.",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Install the latest Muse update and minimize the app's granted access.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:meta-muse",
            "to": "latest",
            "why": "The report says Meta has pushed a fix but gives no version.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Meta Muse on macOS (version not stated)",
          "any": false,
          "status": "confirmed",
          "source": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any Muse assistant task using dictation or connected apps",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "The Muse macOS app, its dictation endpoint setting and the user's granted files, email, messages, calendar or shopping access",
          "status": "confirmed",
          "source": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
        },
        "approval": {
          "value": "A program running as the logged-in user can change the undocumented setting without extra permissions",
          "mode": "none-required",
          "status": "confirmed",
          "source": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
        },
        "inputControl": "tool-provider",
        "agentAction": "Muse sends dictated input to the attacker-controlled endpoint and uses the captured account token.",
        "harm": "credential-theft",
        "divergence": "none",
        "reach": {
          "value": "Muse account chat history and the services the user granted to Muse",
          "kinds": [
            "inbox",
            "private-repositories",
            "browser-session"
          ],
          "status": "confirmed",
          "source": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
        }
      },
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
