# Security researcher shows hidden Muse setting could let attackers turn Muse into backdoor

Digest AI · Agents & Tools · published 2026-09-21T17:00:00Z

Canonical: https://digestai.news/story/security-researcher-shows-hidden-muse-setting-could-let-attackers-turn

## Summary

Security researcher Patrick Wardle released a proof‑of‑concept on September 21 showing that a hidden preference in Meta's Muse assistant for macOS can be changed to redirect voice dictation to an attacker‑controlled endpoint. The setting, stored under the name endovoyagerdictationendpoint, can be altered by any program running as the logged‑in user, allowing the attacker to read what the user says, inject additional commands that Muse will obey, and capture the session token that identifies the user's Muse account.

Wardle demonstrated that with the stolen token he could control Muse on other devices, such as an iPhone, to reveal location, scan Bluetooth devices, and list smart‑home commands. The attack does not bypass macOS protections on passwords and does not compromise Meta's cloud isolation. No fix is available yet, and Wardle advises users to quit or uninstall Muse, audit its permissions, avoid voice input, and change passwords on linked accounts if they suspect compromise.

## Key points

- The hidden preference endovoyagerdictationendpoint can be altered to send Muse dictation to an attacker‑controlled address.
- Attack requires code execution as the logged‑in user, then can read dictation, inject instructions, and steal the Muse session token.
- No patch exists; users should quit or remove Muse, review its permissions, avoid voice input, and change passwords if compromised.

## Why it matters

The flaw shows how a seemingly benign AI assistant can become a backdoor, highlighting the need for tighter OS‑level isolation and prompting users to reconsider granting broad permissions to AI agents.

## Sources

1. [One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor](https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html) (thehackernews.com, 2026-09-21)

## Cite

Digest AI, "Security researcher shows hidden Muse setting could let attackers turn Muse into backdoor", 21 September 2026, https://digestai.news/story/security-researcher-shows-hidden-muse-setting-could-let-attackers-turn

---

Written by Digest AI's editorial model from the linked sources; the sources are the record. Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse
JSON: https://digestai.news/story/security-researcher-shows-hidden-muse-setting-could-let-attackers-turn.json
