- Security researcher Patrick Wardle disclosed a vulnerability in Meta’s new Muse AI assistant for Mac that allows malware to hijack dictation and steal account tokens.
- The flaw exploits an undocumented setting that redirects user voice prompts to an attacker-controlled program instead of Meta’s servers, requiring only existing code execution on the Mac.
- An attacker can read dictated text, inject additional instructions, capture the Muse authentication token, and remotely control the assistant on any linked device.
- Meta has released a “fix” according to Wardle, but no security advisory has been published, and users are advised to quit or remove Muse until confirmation.
A Mac security researcher demonstrated that malware already running on a system can quietly hijack Meta‘s newly launched Muse AI assistant and weaponize the broad access users grant it. Patrick Wardle released a proof-of-concept on September 21 showing how an attacker can change a hidden setting to redirect voice dictation away from Meta’s servers.
Muse, which Meta launched this month in the United States, works across files, email, messages, calendar, shopping and smart-home apps using whatever permissions the owner chooses. The flaw only works when an attacker already runs code as the logged-in user, but Wardle told The Hacker News that a remote attacker could steal the Muse token through a ClickFix trick that fools the user into running a single command.
macOS normally prevents one app from accessing another’s files or saved logins, so typical malware is limited. An attacker who quietly steers Muse instead gets everything the user allowed the app to do. Wardle warns that security software may not notice because the commands come from Muse, a normal signed app.
The undocumented setting is stored in the Mac app’s preferences under the name endo_voyager_dictation_endpoint. Any program running as the logged-in user can point it at an attacker-controlled address without extra permissions. After that, dictation no longer reaches Meta—the audio and text go to a small program the attacker runs on the same Mac.
Wardle demonstrated three attack capabilities: reading dictated text, adding extra instructions that Muse trusts, and capturing a token that signs in to the user’s Muse account. That token allows the attacker to read chat history and control the assistant directly on any device where Muse is signed in. In his tests, Wardle directed the Muse app on his own iPhone to report its exact location and run a Bluetooth scan of nearby devices.
The attack does not defeat macOS’s password protections, does not break Meta‘s cloud system, and relies on Muse acting with access it already holds. Wardle chose full disclosure without reporting the flaw to Meta first, arguing it is often the fastest way to get such bugs fixed. He said Meta has since pushed out a “fix,” pointing to a post on X, though The Hacker News could not confirm what the change does and has reached out to Meta for comment.
Until Meta confirms a fix, users should quit or remove Muse, review and revoke unnecessary permissions, avoid voice input, and never paste commands from websites into Terminal. Wardle plans to present more AI assistant flaws at the Objective by the Sea conference in Hawaii in November.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
