Security researcher shows hidden Muse setting could let attackers turn Muse into backdoor
Security researcher Patrick Wardle released a proof‑of‑concept on September 21 showing that a hidden preference in Meta's Muse assistant for macOS can be changed to redirect voice dictation to an attacker‑controlled endpoint. The setting, stored under the name endovoyagerdictationendpoint, can be altered by any program running as the logged‑in user, allowing the attacker to read what the user…
Key points
- The hidden preference endovoyagerdictationendpoint can be altered to send Muse dictation to an attacker‑controlled address.
- Attack requires code execution as the logged‑in user, then can read dictation, inject instructions, and steal the Muse session token.
- No patch exists; users should quit or remove Muse, review its permissions, avoid voice input, and change passwords if compromised.
Wardle demonstrated that with the stolen token he could control Muse on other devices, such as an iPhone, to reveal location, scan Bluetooth devices, and list smart‑home commands. The attack does not bypass macOS protections on passwords and does not compromise Meta's cloud isolation. No fix is available yet, and Wardle advises users to quit or uninstall Muse, audit its permissions, avoid voice input, and change passwords on linked accounts if they suspect compromise.
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
thehackernews.com · 21 September 2026
Loading the full article…
This text was published by thehackernews.com and written by The Hacker News. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Agents & Tools
All →- Jun Kim joins Hugging Face to lead oMLX for the MLX community · 1 src
- Anthropic's Claude reportedly down for thousands of users on September 21 · 2 src
- Nvidia releases SoL-Pi, cutting coding agent token traffic by up to 49% · 1 src
- TypeSafe AI launches Jev, a System One model for decision-making, not text generation · 15 src
- Google launches Gemini 3.8 Live voice model for developers · 3 src
Comments
via GitHub Discussions