DigestAI news desk

Cut through the AI noise.

Agents & Tools3 min read

Security researcher shows hidden Muse setting could let attackers turn Muse into backdoor

Security researcher Patrick Wardle released a proof‑of‑concept on September 21 showing that a hidden preference in Meta's Muse assistant for macOS can be changed to redirect voice dictation to an attacker‑controlled endpoint. The setting, stored under the name endovoyagerdictationendpoint, can be altered by any program running as the logged‑in user, allowing the attacker to read what the user…

1 source

Key points

  • The hidden preference endovoyagerdictationendpoint can be altered to send Muse dictation to an attacker‑controlled address.
  • Attack requires code execution as the logged‑in user, then can read dictation, inject instructions, and steal the Muse session token.
  • No patch exists; users should quit or remove Muse, review its permissions, avoid voice input, and change passwords if compromised.

Wardle demonstrated that with the stolen token he could control Muse on other devices, such as an iPhone, to reveal location, scan Bluetooth devices, and list smart‑home commands. The attack does not bypass macOS protections on passwords and does not compromise Meta's cloud isolation. No fix is available yet, and Wardle advises users to quit or uninstall Muse, audit its permissions, avoid voice input, and change passwords on linked accounts if they suspect compromise.

Full story from thehackernews.com · by The Hacker News · via Search: MuseOpen source ↗

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

thehackernews.com · 21 September 2026

Loading the full article…

This text was published by thehackernews.com and written by The Hacker News. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗

Topics · follow one to build your own front page
MetaPatrick Wardle

The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.

Comments

via GitHub Discussions

More in Agents & Tools

All →

Related stories