Meta's Muse Assistant Can Be Turned Into a Backdoor Through a Hidden Dictation Setting
Meta's Muse Assistant Can Be Turned Into a Backdoor Through a Hidden Dictation Setting
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. The attack changes a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta — and from there the attacker can read everything dictated, inject instructions Muse trusts and acts on, and capture the token that signs in to the Muse account.
Muse is the personal AI agent Meta launched in the United States this month. Once a user turns it on, it can work across their files, email, messages, calendar, shopping, and smart-home apps, using whatever access the person chooses to give it. That access is the point of the attack: macOS normally prevents one app from reading another's files, microphone, camera, or saved logins, which limits ordinary malware. An attacker who quietly steers Muse instead inherits everything the user allowed the app to do — and because the commands come from Muse, a normal signed application, security software has little reason to notice them.
The Setting That Shouldn't Exist
The flaw sits in an undocumented preference that decides where Muse sends dictation. Any program running as the logged-in user can point the setting — named endo_voyager_dictation_endpoint in the Mac app's preferences — at an address the attacker controls, without needing extra permissions. After that, spoken prompts no longer reach Meta: the audio and the text go to a small program the attacker is running on the same Mac.
From that position, Wardle demonstrated three capabilities. First, reading what the user dictates. Second, adding extra instructions that Muse trusts and acts on. Third, capturing the token that signs in to the Muse account — and because a Muse account can be signed in on multiple devices, that token works everywhere. Wardle used it to direct the Muse app on his own iPhone to report its exact location, run a Bluetooth scan of nearby devices, and list the smart-home commands it could send. In his tests, the assistant only drafted messages rather than sending them on its own.
The attack needs a foothold: it cannot break into a Mac on its own, and it does not defeat the macOS protections that stop one app from reading another app's saved passwords and tokens. But Wardle told The Hacker News a remote attacker could reach the same place through a ClickFix trick, which fools the user into running a single pasted command with nothing to download or install. Wardle did not report the flaw to Meta before going public, choosing full disclosure so users would understand the risk. Meta has since pushed what he called a "fix," but The Hacker News could not confirm what the change does, and Meta has published no security advisory.
What Should You Do?
- Quit Muse, or remove it until Meta confirms and documents a real fix.
- Review the apps and permissions Muse holds and revoke anything it does not need — less access means less for an attacker to inherit.
- If the Mac may already be compromised, treat the Muse account and everything connected to it as exposed and change those passwords.
- Avoid Muse's voice input — avoiding dictation closes the exact path Wardle demonstrated.
- Never paste commands from websites or messages into Terminal — that is how a ClickFix attack starts.
The WAF Angle
Muse is the clearest example yet of a rule WAFNinja keeps returning to: the agent's permission graph is the new perimeter. Every scope the user granted became an attacker capability, and the pivot was a single undocumented config knob deciding where user data flows. Two lessons generalize. First, AI agent tokens are production-grade credentials — treat them like API keys: monitor their use, scope their reach, and assume they are what malware wants most. Second, ClickFix is a web problem: the fake-captcha pages that talk users into running commands are web content your WAF can see, flag, and block before the paste ever reaches a Terminal. Vendors, meanwhile, should inventory every setting that silently reassigns where user data goes — undocumented endpoints are backdoors waiting for malware that knows the preference key.