NewsTradingSentimentEventsCommunityBriefing
Tech

Meta Muse Mac Flaw Lets Attackers Hijack AI Dictation

By Tech Desk · · 2 min read
A flat vector illustration of a microphone icon overlaid with a red prohibition sign.

A hidden setting in Meta's Muse assistant on Mac allows existing malware to intercept voice commands and steal account tokens.

Key points

  • A hidden Mac setting in Meta Muse allows existing malware to intercept voice dictation and redirect it to attackers.
  • Attackers can steal authentication tokens to control the AI assistant across all linked devices, including iPhones.
  • Security researcher Patrick Wardle advised users to remove Muse or revoke its broad permissions until a confirmed fix is verified.

Security researchers have identified a significant vulnerability in Meta's new Muse AI assistant for Mac. The flaw allows malware already present on a device to hijack the assistant's voice input functionality, effectively turning a helpful tool into a surveillance channel for attackers.

The issue stems from a hidden configuration setting that determines where dictation data is sent. By altering this setting, an attacker can redirect user voice prompts away from Meta's servers and toward their own local software. This bypasses standard security checks because the commands appear to come from a trusted, signed application rather than malicious code.

Hidden setting redirects voice data

Patrick Wardle, a security researcher, demonstrated this exploit by modifying an undocumented preference named endo_voyager_dictation_endpoint. This change does not require additional permissions, meaning any process running as the current user can execute it. Once altered, audio and text from the user's microphone are captured by a local program controlled by the attacker instead of being processed by Meta.

Wardle noted that this technique works even if the attacker is remote, provided they can trick the user into running a single command. This method, known as a ClickFix, avoids downloading large malware packages. The attack leverages the broad permissions users typically grant to AI assistants, such as access to emails, calendars, and smart home devices.

Attackers gain full account control

Beyond intercepting voice commands, the exploit allows attackers to capture the authentication token used by Muse. This token grants access to the user's account history and allows the attacker to issue commands to the assistant from any linked device. In tests, this included directing the assistant on an iPhone to report its location and scan nearby Bluetooth devices.

The danger is heightened because security software may not flag these actions. Since the commands originate from Muse itself, a legitimate signed app, they blend in with normal activity. Wardle emphasized that the assistant only drafts messages in his tests, but the underlying control over the agent's capabilities presents a serious risk.

Users should limit assistant permissions

The Hacker News reported that Meta has reportedly pushed a fix, though the company has not published a detailed security advisory. Wardle chose full disclosure to ensure users understand the risk quickly. Until the fix is confirmed, experts advise users to quit or remove the Muse application entirely to eliminate the attack surface.

Additionally, users should review and revoke unnecessary permissions granted to Muse, such as access to email or smart home controls. If a Mac may have been compromised, changing passwords for the Muse account and any connected services is recommended. Avoiding voice input for this specific assistant is also a temporary mitigation strategy.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories