The Maivia Gazette

Verified AI news, every morning

Security

Researcher publishes working exploit turning Meta's Muse assistant into a Mac backdoor

Patrick Wardle says an undocumented dictation setting can be rewritten by any local process, redirecting a user's spoken audio to an attacker's server.

Overhead view of a desk microphone whose cable curves away from a laptop into a sealed grey crate.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Patrick Wardle, founder of the Objective-See Foundation and author of "The Art of Mac Malware," has urged Mac users not to install Meta's new Muse AI assistant, publishing proof-of-concept code for a zero-day he calls "not-a-mused." He disclosed the issue in a thread on X alongside a working exploit on GitHub. "Please don't install," he wrote. "It's trivial to turn Muse into the ultimate backdoor." The flaw centres on an undocumented Muse setting, endo_voyager_dictation_endpoint. Wardle showed that any local process can change it without elevated privileges. Once the endpoint is redirected, audio a user dictates to Muse is sent to an attacker's server instead of Meta's, and the accompanying code indicates this can allow capture of that audio. The severity comes from what the assistant is already permitted to reach. Muse holds broad access to files, the microphone, camera, location, calendar and even linked iPhones, so a compromise of the app could hand an attacker the same reach across a victim's machine and phone data. The technique requires code already running on the Mac rather than remote access, but it needs no administrator rights and no user interaction with the setting.

Sources

  1. iTnewsSecurity researcher says donPublished · fetched
  2. The Hacker NewsOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorPublished · fetched

Also in this edition