search

LEMON BLOG

Hidden Meta Muse Setting Could Let Attackers Turn The AI Assistant Into A Backdoor

A hidden setting inside the Mac version of Meta's Muse AI assistant could potentially allow malware already running on a computer to hijack the assistant and abuse the extensive permissions granted to it. Security researcher Patrick Wardle demonstrated the issue in a proof-of-concept released on 21 September, showing how an attacker could redirect Muse's voice dictation traffic away from Meta and towards infrastructure under their control. The technique does not allow an attacker to break into a Mac by itself, but it could significantly increase the capabilities of malware that has already gained access to the logged-in user's account.

Hidden Meta Muse Setting Could Let Attackers Turn The AI Assistant Into A Backdoor

A hidden setting inside the Mac version of Meta's Muse AI assistant could potentially allow malware already running on a computer to hijack the assistant and abuse the extensive permissions granted to it. Security researcher Patrick Wardle demonstrated the issue in a proof-of-concept released on 21 September, showing how an attacker could redirect Muse's voice dictation traffic away from Meta and towards infrastructure under their control. The technique does not allow an attacker to break into a Mac by itself, but it could significantly increase the capabilities of malware that has already gained access to the logged-in user's account.

The concern is particularly significant because Muse is designed to operate across a wide range of personal services. Depending on what permissions the user grants, the AI assistant can interact with files, email, messages, calendars, shopping services and smart-home applications. Hijacking an application with that level of legitimate access could effectively give an attacker a trusted gateway into information and functions that ordinary malware might otherwise struggle to reach.

The Attack Requires Existing Access To The Mac

The vulnerability does come with an important limitation: an attacker must already be able to execute code under the currently logged-in macOS user. The flaw therefore cannot independently compromise a Mac or bypass the operating system's security protections. Instead, it becomes useful after another attack has already established a foothold.

Wardle also warned that remote attackers could potentially reach this stage through techniques such as ClickFix. These attacks typically trick victims into copying and running a command in Terminal under the belief that they are fixing a problem or completing a verification process. In this scenario, the victim may not need to download a traditional application or installer because simply executing the supplied command can provide the attacker with the necessary access.

A Hidden Setting Controls Where Voice Dictation Goes

At the centre of the proof-of-concept is an undocumented Muse preference called endo_voyager_dictation_endpoint. This setting determines where the Mac application sends voice dictation data when a user taps the microphone and speaks a prompt. Wardle found that software running as the logged-in user could change this setting without requesting additional system permissions.

An attacker could therefore replace Meta's normal endpoint with an address controlled by the attacker. Once modified, spoken prompts would no longer travel directly to their intended destination. Instead, both the audio and corresponding text could first be redirected to a malicious program running on the Mac.

Why Hijacking Muse Could Be More Dangerous Than Ordinary Malware

macOS normally places restrictions around access to sensitive resources such as microphones, cameras, files and credentials. Applications generally need permission before accessing protected information, which limits what newly installed malware can immediately do. Muse, however, may already have been deliberately granted broad permissions by its owner because those permissions are necessary for the assistant to perform useful tasks.

This creates an opportunity for an attacker to abuse the AI assistant rather than requesting those permissions directly. Instead of appearing as unfamiliar malicious software trying to access protected resources, actions could originate from Muse itself, which is a legitimate signed application. That could potentially make suspicious activity more difficult for both users and some security tools to recognise.

Attackers Could Modify Instructions Sent To Muse

Wardle demonstrated several capabilities after redirecting Muse's dictation traffic. The first was simply being able to read what the user dictated, exposing potentially private prompts and conversations. More significantly, the attacker could inject additional instructions into the prompt before forwarding it onwards.

Muse could then process those additional instructions as though they were part of the user's legitimate request. This creates a path for an attacker to influence what the assistant does while taking advantage of the permissions already granted to it. From the victim's perspective, the interaction could still appear to be an ordinary Muse session.

Muse Authentication Token Could Also Be Captured

The proof-of-concept also demonstrated that the redirected communication could expose a token used to authenticate the user's Muse account. An attacker who obtains this token could potentially access the account's chat history and interact with the assistant directly. This expands the attack beyond simply intercepting one voice prompt.

Importantly, Muse accounts can reportedly be accessed across multiple devices. Wardle demonstrated using the captured authentication token to issue instructions to Muse running on his own iPhone, including asking it to report the device's precise location, scan for nearby Bluetooth devices and identify smart-home commands available to the assistant. In his testing, however, Muse only prepared messages rather than automatically sending them.

The Attack Does Not Break macOS Password Protections

The proof-of-concept does not mean that Muse can simply bypass every macOS security mechanism. Wardle stressed that the attack does not defeat protections that prevent one application from directly reading another application's saved passwords or authentication tokens. Instead, the technique works because Muse itself sends its own authentication token as part of the redirected dictation process.

In other words, the attacker is not directly breaking into protected storage. The attacker is manipulating Muse into exposing or using information that the application is already authorised to access. The demonstration also does not indicate that Meta's cloud-side isolation system for separating individual users' agents was compromised.

Why AI Assistants Create A New Security Challenge

AI agents such as Muse are designed to become increasingly useful by connecting to more applications and personal information. That convenience also makes them particularly attractive targets because compromising one trusted assistant could potentially provide access to several otherwise separate services. The more permissions an AI agent receives, the more important the security of the agent itself becomes.

This creates a different security model from traditional applications. An attacker may no longer need to compromise every individual email, calendar or smart-home application directly if they can instead manipulate the assistant that already has legitimate access to those systems. As AI agents become capable of taking more autonomous actions, protecting the boundary between user instructions and attacker-controlled instructions will become increasingly important.

Meta Reportedly Introduced A Fix

Wardle said he did not privately disclose the vulnerability to Meta before releasing his findings publicly. He instead chose full disclosure, arguing that making users aware of the risk could encourage faster remediation. He later indicated that Meta had pushed out what he described as a fix, although the exact technical changes were not independently confirmed at the time of the report.

Meta had also not published a dedicated security advisory explaining precisely what had been changed. This means it remains unclear whether the undocumented dictation endpoint was removed, restricted or otherwise protected against modification. Users should therefore ensure they are running the latest available version of Muse if they choose to keep the application installed.

What Mac Users Can Do

Until the protection is clearly documented, users concerned about the issue can reduce their exposure by reviewing how Muse is configured. Removing permissions that the assistant does not genuinely need limits what could potentially be accessed if it were ever hijacked. Users who believe their Mac may already have been compromised should also consider connected accounts and Muse sessions potentially exposed and take appropriate steps to secure them.

Avoiding Muse's voice dictation feature would also close the specific attack path demonstrated in Wardle's proof-of-concept. More generally, users should never paste or execute Terminal commands simply because a website, pop-up or unsolicited message instructs them to do so. That behaviour has become an increasingly common entry point for ClickFix-style attacks.

Apple Dictation Versus Muse's Own Implementation

Wardle also questioned Meta's decision to implement its own dictation mechanism that sends voice data away from the Mac rather than relying on Apple's existing dictation capabilities. In his view, the custom implementation created an additional attack surface that would not otherwise have been necessary. The undocumented endpoint controlling where dictation was sent ultimately became the key mechanism used in the demonstration.

The issue highlights a broader challenge for developers building desktop AI agents. Adding custom mechanisms for features already provided securely by the operating system can introduce new configuration paths and security assumptions. Every additional component capable of redirecting sensitive information needs to be designed with the possibility of local compromise in mind.

Final Thoughts

The Muse proof-of-concept is a useful reminder that the security risk surrounding AI assistants is not limited to the AI model itself. Applications such as Muse increasingly sit between users and their files, messages, calendars, smart-home systems and other sensitive services. If attackers can manipulate those trusted applications, they may be able to inherit the permissions users willingly granted to the assistant.

The demonstrated flaw does require an attacker to already have some level of access to the Mac, so it should not be viewed as a standalone remote compromise. Nevertheless, it shows how a relatively small configuration weakness can become much more powerful when it exists inside an AI agent with extensive permissions. As personal AI assistants become more capable and connected, securing the mechanisms that control their actions may prove just as important as securing the underlying models themselves.

Gkash Connects Directly To PayNet For DuitNow QR, ...
China-Aligned TA419 Targets U.S. AI Policy Experts...

Related Posts

 

Comments 0

Loading latest comments...
Sunday, 04 October 2026

Captcha Image

LEMON VIDEO CHANNELS

Step into a world where web design & development, gaming & retro gaming, and guitar covers & shredding collide! Whether you're looking for expert web development insights, nostalgic arcade action, or electrifying guitar solos, this is the place for you. Now also featuring content on TikTok, we’re bringing creativity, music, and tech straight to your screen. Subscribe and join the ride—because the future is bold, fun, and full of possibilities!

My TikTok Video Collection