[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fKQ_2lypPK-KqTQOppLGkWndnomSnbMwPvz3bn2sqX3o":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"1c4ea427-3869-42eb-8303-dccf29033440","One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor","one-hidden-meta-muse-setting-could-let-attackers-turn-the-ai-assistant-into-a-ba-f549f0","Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in","Security researcher Patrick Wardle discovered a vulnerability in Meta's Muse AI assistant for Mac that allows attackers to hijack user dictation. By altering a hidden setting, malware already on a user's system can redirect voice prompts to an attacker, granting them access to dictated information, the ability to inject commands, and session tokens. This allows for control of the AI assistant across multiple devices, including iPhones, and access to connected apps and smart home devices.","Hidden setting in Meta's Muse AI assistant on Mac allows attackers to hijack dictation.","One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Swati KhandelwalSep 22, 2026Vulnerability \u002F Artificial Intelligence Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in the Mac version of Muse, and it only works if an attacker can already run code as the logged-in user. It is not a way to remotely break into a Mac. Muse is the personal AI agent Meta launched this month in the United States. Once a user turns it on, it can work across their files, email, messages, calendar, shopping and smart-home apps, using whatever access the person chooses to give it. That access is the point, Wardle says. He urged people not to install Muse, calling it \"trivial to turn Muse into the ultimate backdoor.\" macOS normally prevents one app from accessing another app's files, microphone, camera, or saved logins, so ordinary malware is limited in what it can access. An attacker who can quietly steer Muse instead gets everything the user allowed the app to do. Wardle also warns that security software may not notice, because the commands come from Muse, a normal signed app, rather than from something that looks like malware. The setting he found is undocumented and decides where Muse sends dictation. It is stored in the Mac app's preferences under the name endo_voyager_dictation_endpoint, and any program running as the logged-in user can point it at an address the attacker controls, without needing extra permissions. After that, the dictation no longer goes to Meta. When the user speaks a prompt, the audio and the text go to a small program the attacker is running on the same Mac. From there, Wardle showed three things an attacker can do: read what the user dictated, add extra instructions that Muse trusts and acts on, and take the token that identifies the user's Muse session and use it to control the assistant directly. Because a Muse account can be signed in on multiple devices, the attack does not stop at the Mac. Using a stolen session, Wardle directed the Muse app on his own iPhone to report its exact location, run a Bluetooth scan of nearby devices, and list the smart-home commands it could send. In his tests, the assistant only drafted messages rather than sending them on its own. Wardle also pointed to what the attack does not do. It does not defeat the part of macOS that stops one app from reading another app's saved passwords. Instead of stealing Muse's stored login tokens, it makes Muse itself act, using access the app already has. And it does not show that Meta's cloud system, which the company built to keep each user's agent walled off, was broken. What Mac Users Can Do Now With no patch available, a Mac user can only limit the exposure: Quit Muse, or remove it, until Meta fixes the problem. Review the apps and permissions Muse holds, and revoke any it does not need, so there is less for an attacker to access. If the Mac may already be compromised, treat the connected accounts as exposed and change their passwords. Because the attack needs the user to dictate, avoid Muse's voice input, which closes the exact path shown. Meta has put a lot of weight on Muse's security. It built the agent to run in a separate cloud system that keeps each user's data apart from others, with a checking layer meant to approve the actions Muse takes. This flaw sits in the Mac app instead, not in that cloud design. Wardle argues Meta created the weak point itself by building its own way to handle dictation that sends the audio off the device, rather than using Apple's dictation, which runs on the Mac. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, endpoint security, MacOS, Vulnerability ⚡ Top Stories This Week Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. How to Evaluate a Unified Security Platform Using a One-Incident Test Stop Trying to Control AI Behavior. Control What AI Can Reach ⭐ Featured Resources Validation Summit ’26: See How Pen Testing, Exposure Validation and BAS Work Together Red Teams: Learn How Attack Path Chaining Changes Automated Security Testing Turn Threat Intelligence Into Verified Risk With Threat-Led Penetration Testing Deploy Browser Security Monitoring in Minutes With a Single Header","https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fone-hidden-meta-muse-setting-could-let.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjjZLVTtI-AEbGRQqJ7aGa0tbXedD5L6P7VCEKIOGXOBZe7S3mhA-PnoHVEoZf3LBMzhcZSIX5sCTveGyZ-8qAqyAVaMXfEoxPL70OIESq-Iolqjkv8GuDjcVs1Jgh3k3SoOOGPDWFr6Lmk83avLqG1whcaiDclv5waXYhCuEqXk569wfwV8Ilrmvv3IKE\u002Fs1600\u002Fmuse.jpg","2026-09-22T06:33:57+00:00","2026-09-22T08:00:29.46545+00:00",8,[18,21,24,26],{"name":19,"type":20},"Muse","product",{"name":22,"type":23},"Meta","vendor",{"name":25,"type":20},"macOS",{"name":27,"type":28},"attacker","threat_actor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,37,42,47],{"category":36},{"id":29,"icon":31,"name":32,"slug":33},{"category":38},{"id":39,"icon":31,"name":40,"slug":41},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":46,"value":19,"context":54},"Meta's AI assistant on Mac, exploited to act as a backdoor"]