One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
A security researcher has discovered a vulnerability in Meta's Muse AI assistant for Mac, allowing attackers to silently hijack the app and use it as a backdoor. By changing a hidden setting, an attacker can redirect all voice input to their own program, gaining access to the user's data and potentially controlling the assistant. Meta has not yet released a patch, and users are advised to quit the app or review permissions to mitigate the risk.
A security researcher, Patrick Wardle, has identified a critical vulnerability in Meta’s Muse AI assistant for macOS, presenting a significant backdoor risk. The flaw allows an attacker to silently take over the assistant and leverage its existing permissions to access user data and potentially control the application.
Muse, launched this month, integrates with various apps on a Mac, including files, email, messages, calendar, and smart-home applications, granting it broad access to user data based on the permissions the user provides. Wardle discovered a hidden setting – `endo_voyager_dictation_endpoint` – that allows an attacker to redirect all voice input to their own program, bypassing standard macOS security measures that prevent apps from accessing each other’s data.
To exploit this vulnerability, an attacker must first have malware already running on the Mac. Once the setting is changed, all voice commands are sent to the attacker’s program, enabling them to read dictated text, add instructions Muse trusts and acts upon, and steal the user’s Muse session token. This token can then be used to control the assistant directly, even on other devices where the account is logged in.
Tests showed that the attack doesn't bypass macOS's protections against app-to-app password theft. Instead, it leverages Muse's existing permissions, effectively turning the assistant into a conduit for an attacker. Furthermore, the vulnerability resides within the Mac app itself, not in Meta’s cloud-based architecture designed to isolate user data.
**What Mac Users Can Do Now:**
- Quit Muse, or remove it, until Meta fixes the problem.
- Review the apps and permissions Muse holds, and revoke any it does not need, so there is less for an attacker to access.
- If the Mac may already be compromised, treat the connected accounts as exposed and change their passwords.
- Because the attack needs the user to dictate, avoid Muse's voice input, which closes the exact path shown.
Meta has emphasized its commitment to Muse’s security, building the agent within a separate cloud system to keep user data isolated. However, the vulnerability lies within the Mac app itself, highlighting a design flaw that allows an attacker to exploit existing permissions rather than breaking the cloud architecture.
