Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Crypto’s Wild Market Swings Are Fading, Solstice CEO Says

    September 22, 2026

    Stem cells reverse stroke damage and restore movement in mice

    September 22, 2026

    Strohm’s pilot ultra-deepwater TCP flowline to hit the water off Brazil in early 2027

    September 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Crypto’s Wild Market Swings Are Fading, Solstice CEO Says
    • Stem cells reverse stroke damage and restore movement in mice
    • Strohm’s pilot ultra-deepwater TCP flowline to hit the water off Brazil in early 2027
    • Trump’s Greenland Deal Is the End of a Pointless Conflict
    • Russian strikes on Ukraine kill three as Zelenskyy in US for UN summit | Drone Strikes News
    • Caution versus ambition: strategy debate dominates Lib Dem conference | Liberal Democrats
    • UK not ‘on the slide’, Burnham to tell UN as he gears up for first meeting with Trump – UK politics live | Politics
    • Merz’s woes cast doubt over EU’s €2tn budget deal
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.

    It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.

    The flaw is in the Mac version of Muse, and it only works if an attacker can already run code as the logged-in user. It cannot break into a Mac on its own. But Wardle told The Hacker News that a remote attacker could hijack Muse and steal its token through a ClickFix trick, which fools the user into running a single command with nothing to download or install.

    Muse is the personal AI agent Meta launched this month in the United States. Once a user turns it on, it can work across their files, email, messages, calendar, shopping and smart-home apps, using whatever access the person chooses to give it.

    That access is the point, Wardle says. He urged people not to install Muse, calling it “trivial to turn Muse into the ultimate backdoor.”

    Cybersecurity

    macOS normally prevents one app from accessing another app’s files, microphone, camera, or saved logins, so ordinary malware is limited in what it can access. An attacker who can quietly steer Muse instead gets everything the user allowed the app to do.

    Wardle also warns that security software may not notice, because the commands come from Muse, a normal signed app, rather than from something that looks like malware.

    The setting he found is undocumented and decides where Muse sends dictation. It is stored in the Mac app’s preferences under the name endo_voyager_dictation_endpoint, and any program running as the logged-in user can point it at an address the attacker controls, without needing extra permissions.

    After that, the dictation no longer goes to Meta. When the user speaks a prompt, the audio and the text go to a small program the attacker is running on the same Mac.

    From there, Wardle showed three things an attacker can do: read what the user dictated, add extra instructions that Muse trusts and acts on, and capture a token that signs in to the user’s Muse account, then use it to read the account’s chat history and control the assistant directly.

    Because a Muse account can be signed in on multiple devices, an attacker with the token can give orders to Muse on any of them, not just the Mac, Wardle said. He used it to direct the Muse app on his own iPhone to report its exact location, run a Bluetooth scan of nearby devices, and list the smart-home commands it could send. In his tests, the assistant only drafted messages rather than sending them on its own.

    Wardle also pointed to what the attack does not do. It does not defeat the part of macOS that stops one app from reading another app’s saved passwords and tokens. Muse sends its token along with the redirected dictation, and the attack works by getting Muse to act with access it already has. And it does not show that Meta’s cloud system, which the company built to keep each user’s agent walled off, was broken.

    Wardle said he did not report the flaw to Meta before going public. He chose full disclosure so users would understand the risk, and because it is often the fastest way to get such bugs fixed.

    Cybersecurity

    He said Meta has since pushed out what he called a “fix,” pointing to a post on X. The Hacker News could not confirm what the change does and has reached out to Meta for comment. Meta has not published a security advisory.

    What Mac Users Can Do Now

    Until Meta confirms a fix, a Mac user can limit the exposure:

    • Quit Muse, or remove it.
    • Review the apps and permissions Muse holds, and revoke any it does not need, so there is less for an attacker to access.
    • If the Mac may already be compromised, treat the Muse account and the accounts connected to it as exposed, and change their passwords.
    • Because the attack needs the user to dictate, avoid Muse’s voice input, which closes the exact path shown.
    • Do not run commands that a website or message tells you to paste into Terminal, which is how a ClickFix attack starts.

    Meta has put a lot of weight on Muse’s security. It built the agent to run in a separate cloud system that keeps each user’s data apart from others, with a checking layer meant to approve the actions Muse takes. This flaw sits in the Mac app instead, not in that cloud design.

    Wardle argues Meta created the weak point itself by building its own way to handle dictation that sends the audio off the device, rather than using Apple’s dictation, which runs on the Mac.

    He said he has found more flaws in AI assistants, including in much more widely used apps, which he has reported to the vendors and plans to present at the Objective by the Sea conference in Hawaii in November.

    Assistant Attackers Backdoor hidden Meta Muse Setting Turn
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CrowdSec Confirms Source Code Stolen in Supply Chain Attack

    Rust Team Members and Popular Crate Owners Targeted via Video Calls

    Microsoft to retire Microsoft 365 Companion apps in December

    RatHat Android Trojan Uses AI for Automation

    Meta’s Muse is outpacing ChatGPT’s early mobile launch

    CISA alerts of active exploitation of three Linux kernel flaws

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Crypto’s Wild Market Swings Are Fading, Solstice CEO Says

    September 22, 2026

    Stem cells reverse stroke damage and restore movement in mice

    September 22, 2026

    Strohm’s pilot ultra-deepwater TCP flowline to hit the water off Brazil in early 2027

    September 22, 2026

    Trump’s Greenland Deal Is the End of a Pointless Conflict

    September 22, 2026
    Latest Posts

    Google Assistant will disappear from your phone next month

    August 5, 2026

    Pope Leo Will Visit Peru, Where He Lived for Years, in November

    August 5, 2026

    Forget the goals and PBs – just enjoy it | Sport

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Crypto’s Wild Market Swings Are Fading, Solstice CEO Says

    September 22, 2026

    Stem cells reverse stroke damage and restore movement in mice

    September 22, 2026

    Strohm’s pilot ultra-deepwater TCP flowline to hit the water off Brazil in early 2027

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.