One Hidden Meta Muse Setting Could Let Hackers Steal Your Thoughts
Security researcher Patrick Wardle has demonstrated a significant vulnerability in Meta's Muse AI assistant for Mac that allows malware already present on a system to hijack the application and exploit its extensive permissions. The attack works by modifying an undocumented configuration setting called endo_voyager_dictation_endpoint, which redirects voice prompts from Meta's servers to an attacker-controlled destination. While the vulnerability requires that malicious code already be running on the target Mac under the logged-in user's account, Wardle notes that attackers could achieve this through social engineering techniques like ClickFix, which tricks users into executing commands without downloading files.
The core security concern stems from the broad permissions users typically grant Muse, which can access email, messages, calendars, files, shopping services, and smart home devices. Once an attacker hijacks the application, they inherit all these permissions while appearing as legitimate activity from a properly signed application, making detection by security tools difficult. Wardle's proof of concept showed that attackers could intercept dictation, inject malicious commands, and steal authentication tokens that provide access to the user's Muse account across all devices, not just the compromised Mac.
Wardle chose to publicly disclose the vulnerability without prior notification to Meta, arguing that public disclosure often produces faster fixes and allows users to understand the risks they face. He criticized Meta's decision to implement a custom dictation system that transmits audio off-device rather than using Apple's built-in on-device dictation feature, suggesting this architectural choice created the vulnerability. Meta has reportedly released a fix following the disclosure, though no official security advisory has been published.
The researcher's broader warning extends beyond this specific flaw, noting that he has discovered additional vulnerabilities in other AI assistant applications that are more widely used. This incident highlights a growing security challenge as AI agents gain increasing access to sensitive corporate systems and personal data while security teams lack adequate visibility and controls to manage these risks. Wardle advises users to avoid installing Muse entirely, describing it as trivial to weaponize into what he calls the ultimate backdoor due to the combination of extensive permissions and exploitable implementation.
Stay secure — stay Wavasec. 🔐