{"id":3043,"date":"2026-09-22T06:49:49","date_gmt":"2026-09-22T06:49:49","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3043"},"modified":"2026-09-22T06:49:49","modified_gmt":"2026-09-22T06:49:49","slug":"one-hidden-meta-muse-setting-could-let-attackers-turn-the-ai-assistant-into-a-backdoor","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3043","title":{"rendered":"One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 22, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Artificial Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjjZLVTtI-AEbGRQqJ7aGa0tbXedD5L6P7VCEKIOGXOBZe7S3mhA-PnoHVEoZf3LBMzhcZSIX5sCTveGyZ-8qAqyAVaMXfEoxPL70OIESq-Iolqjkv8GuDjcVs1Jgh3k3SoOOGPDWFr6Lmk83avLqG1whcaiDclv5waXYhCuEqXk569wfwV8Ilrmvv3IKE\/s1700-nu-rw-lo-l85-e365\/muse.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Malware already running on a Mac can quietly take over Meta&#8217;s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a <a href=\"https:\/\/github.com\/pwardle\/not-a-mused\" target=\"_blank\">proof-of-concept<\/a> released on September 21.<\/p>\n<p>It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.<\/p>\n<p>The flaw is in the Mac version of Muse, and it only works if an attacker can already run code as the logged-in user. It is not a way to remotely break into a Mac.<\/p>\n<p>Muse is the personal AI agent Meta <a href=\"https:\/\/www.pbs.org\/newshour\/nation\/meta-launches-personal-ai-agent-muse-to-help-with-everyday-tasks\" target=\"_blank\">launched this month<\/a> in the United States. Once a user turns it on, it can work across their files, email, messages, calendar, shopping and smart-home apps, using whatever access the person chooses to give it.<\/p>\n<p>That access is the point, Wardle says. He urged people not to install Muse, calling it \u00abtrivial to turn Muse into the ultimate backdoor.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>macOS normally prevents one app from accessing another app&#8217;s files, microphone, camera, or saved logins, so ordinary malware is limited in what it can access. An attacker who can quietly steer Muse instead gets everything the user allowed the app to do.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Wardle also warns that security software may not notice, because the commands come from Muse, a normal signed app, rather than from something that looks like malware.<\/p>\n<p>The setting he found is undocumented and decides where Muse sends dictation. It is stored in the Mac app&#8217;s preferences under the name <i>endo_voyager_dictation_endpoint<\/i>, and any program running as the logged-in user can point it at an address the attacker controls, without needing extra permissions.<\/p>\n<p>After that, the dictation no longer goes to Meta. When the user speaks a prompt, the audio and the text go to a small program the attacker is running on the same Mac.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjOw30LVUstcu3e_dWWp9dyEepm3SJaqSLmwrDY-0xTlbuEcAwhwwprHZNC0kHloSzdCmulRsHbqncfULXcA6kYuOC0S3_v6j7oCh6aTdeheFsS6d5fv9OJTo4jmpZHbh386R7hSlplIj_FtPv0g5Vc3Jf6gaC5Sr9vNxnljVS2QL16iCFIpqKt5Bdv0GE\/s1700-nu-rw-lo-l85-e365\/options.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjOw30LVUstcu3e_dWWp9dyEepm3SJaqSLmwrDY-0xTlbuEcAwhwwprHZNC0kHloSzdCmulRsHbqncfULXcA6kYuOC0S3_v6j7oCh6aTdeheFsS6d5fv9OJTo4jmpZHbh386R7hSlplIj_FtPv0g5Vc3Jf6gaC5Sr9vNxnljVS2QL16iCFIpqKt5Bdv0GE\/s1700-nu-rw-lo-l85-e365\/options.jpg\" alt=\"\" border=\"0\" data-original-height=\"477\" data-original-width=\"1429\"\/><\/a><\/div>\n<p>From there, Wardle showed three things an attacker can do: read what the user dictated, add extra instructions that Muse trusts and acts on, and take the token that identifies the user&#8217;s Muse session and use it to control the assistant directly.<\/p>\n<p>Because a Muse account can be signed in on multiple devices, the attack does not stop at the Mac. Using a stolen session, Wardle directed the Muse app on his own iPhone to report its exact location, run a Bluetooth scan of nearby devices, and list the smart-home commands it could send. In his tests, the assistant only drafted messages rather than sending them on its own.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Wardle also pointed to what the attack does not do. It does not defeat the part of macOS that stops one app from reading another app&#8217;s saved passwords. Instead of stealing Muse&#8217;s stored login tokens, it makes Muse itself act, using access the app already has. And it does not show that Meta&#8217;s cloud system, which the company built to keep each user&#8217;s agent walled off, was broken.<\/p>\n<h3>What Mac Users Can Do Now<\/h3>\n<p>With no patch available, a Mac user can only limit the exposure:<\/p>\n<ul>\n<li>Quit Muse, or remove it, until Meta fixes the problem.<\/li>\n<li>Review the apps and permissions Muse holds, and revoke any it does not need, so there is less for an attacker to access.<\/li>\n<li>If the Mac may already be compromised, treat the connected accounts as exposed and change their passwords.<\/li>\n<li>Because the attack needs the user to dictate, avoid Muse&#8217;s voice input, which closes the exact path shown.<\/li>\n<\/ul>\n<p>Meta has put a lot of weight on Muse&#8217;s security. It built the agent to run in a separate cloud system that keeps each user&#8217;s data apart from others, with a checking layer meant to approve the actions Muse takes. This flaw sits in the Mac app instead, not in that cloud design.<\/p>\n<p>Wardle argues Meta created the weak point itself by building its own way to handle dictation that sends the audio off the device, rather than using Apple&#8217;s dictation, which runs on the Mac.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Sep 22, 2026Vulnerability \/ Artificial Intelligence Malware already running on a Mac can quietly take over Meta&#8217;s Muse assistant and use the broad access its owner granted the app,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3044,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3427,622,179,844,235,3488,3489,2317],"class_list":["post-3043","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-assistant","tag-attackers","tag-backdoor","tag-hidden","tag-meta","tag-muse","tag-setting","tag-turn"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3043"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3043\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3044"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3043"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}