One hidden Meta Muse setting could let attackers turn the AI assistant into a backdoor

13 views

Meta Muse is designed to act as a personal AI assistant across a Mac and connected devices – much like the new Siri AI released with…

Benjamin LloydOct 5, 20264 min read

Meta Muse is designed to act as a personal AI assistant across a Mac and connected devices – much like the new Siri AI released with iOS 27. That convenience comes with a serious security concern though: a hidden setting in the macOS app could let malware redirect voice prompts to an attacker.

Security researcher Patrick Wardle demonstrated the problem in a proof of concept he called “not-a-mused”. Note that the vulnerability does not allow a remote attacker to break into every Mac running Muse. The hack only works when malicious code is already running under the logged-in user’s account. 

However, once the code is loaded, Muse’s permissions could give the attacker access to sensitive information and actions the user previously granted to the assistant.

How does the Meta Muse hack work?

The “not-a-mused” attack changes an undocumented Muse preference called “endo_voyager_dictation_endpoint”. This setting controls where Muse sends audio and text when a user dictates a prompt.

Malware can reportedly change this setting without administrator privileges. The attacker uses malware to change the setting, pointing Muse output to a server or program they control. When the user taps Muse’s microphone, the dictated audio and transcript are redirected to the attacker instead of Meta.

Once the attacker has successfully taken control of Muse commands, they can:

  • Read what the user says to Muse.
  • Add instructions to the prompt before Muse processes it.
  • Capture Muse’s authentication token.
  • Use that token to access the user’s Muse account and control the assistant on other signed-in devices (like smartphones and tablets).

The risk to your safety comes from Muse’s broad permissions. Depending on how it is configured, the assistant may be able to interact with files, email, messages, calendars, shopping services, smart-home devices and other connected features. 

Any malicious action appears to come from a legitimate, signed Meta application, which could make it harder for some security tools to identify.

Does this mean every Mac user is at risk?

No. This is a local attack, so the attacker first needs a way to run code on your Mac. That could happen through existing malware, a malicious application or a social-engineering technique such as ClickFix.

ClickFix attacks often show a fake error message or support instruction telling someone to paste a command into Terminal. The victim may believe they are fixing a problem, but the command gives the attacker an opportunity to run malicious code under their account.

The “not-a-mused” vulnerability is in the way the Muse application handles dictation on the local computer. It does not indicate an issue with Meta’s cloud infrastructure, and it does not automatically give an attacker access to every Mac that has Muse installed – only those that have already been compromised by malware.

Meta has reportedly issued a hotfix for “not-a-mused”, although users should still treat the incident as a warning about granting AI assistants extensive access to their personal data.

How can I protect myself?

  • Do not install Meta Muse. This is the simplest way to avoid exposure to this specific flaw. It will also help avoid many of the concerns related to social media companies mining your personal data for profit.
  • Keep macOS and all installed applications updated.
  • Never paste commands into Terminal because a website, pop-up or message tells you to do so.
  • Treat unexpected requests to disable security tools or change system settings as suspicious.
  • Give AI assistants only the permissions they genuinely need. If they don’t need access to your personal data, do not grant permission.
  • Review and revoke Muse permissions for files, email, messaging, location, calendars and smart-home services.
  • If Muse was installed on a Mac that may have been compromised by malware, quit or remove the app.
  • Change the password for your Muse account and any connected services from a trusted device.
  • Sign out of active sessions and enable multifactor authentication on your Facebook account.
  • Avoid using voice dictation in Muse until you have confirmed that the app is fully updated.
  • Run a security scan with Panda Dome if you suspect malware may already be present.

What does this mean for AI assistants?

AI assistants can be more powerful than ordinary apps because users often give them access to several services at once. That creates a larger impact when an assistant is misconfigured or hijacked.

The “not-a-mused” Muse incident also shows why hidden settings deserve careful protection because the attacker did not need to defeat macOS security directly. Instead, the attack attempted to make a trusted application perform actions with permissions the user had already approved.

For now, the safest approach is to avoid installing Meta Muse, limit the permissions granted to AI tools and remain cautious when software asks you to run unfamiliar commands. As always, having a reliable anti-malware tool like Panda Dome will help to stop these kinds of attacks by blocking malware installations earlier.