One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
A security researcher discovered a hidden setting in Meta's Muse AI assistant for Mac that could allow existing malware to hijack the AI, turning it into a backdoor with extensive user access.
Intelligence analysis by Gemini 2.5 Flash

Security researcher Patrick Wardle demonstrated a proof-of-concept where malware already on a Mac can exploit an undocumented Muse setting to redirect user dictation to an attacker. This allows the attacker to read prompts, inject commands, and steal the user's Muse account token, effectively turning the AI assistant into a powerful backdoor.
Imagine you have a super smart robot helper named Muse that can talk to all your apps and devices, like your email or smart lights. A hidden trick was found where if a bad guy's tiny spy program gets onto your computer, it can secretly change a setting in Muse. Now, when you talk to Muse, your words go to the bad guy instead of Muse, letting them pretend to be you and make your robot helper do things you didn't intend, like finding out where you are or looking at your messages.
Analysis
Patrick Wardle
Patrick Wardle, a prominent security researcher, publicly disclosed a significant vulnerability in Meta's newly launched Muse AI assistant for macOS. Wardle's proof-of-concept, released on September 21, demonstrates how an attacker with initial access to a Mac can exploit a hidden setting within the Muse application. His findings underscore the inherent risks associated with AI agents that are granted extensive permissions across a user's digital ecosystem.
Wardle's decision to pursue full disclosure rather than private reporting to Meta was driven by a desire for immediate user awareness and a belief that it is often the fastest route to bug resolution. He also indicated that he has identified similar flaws in other, more widely used AI assistants, which he plans to present at an upcoming security conference. This suggests a broader pattern of potential vulnerabilities in the rapidly evolving AI assistant landscape.
Muse
Meta's Muse AI agent, launched recently in the United States, is designed to integrate deeply with a user's digital life, accessing files, email, messages, calendar, shopping, and smart-home applications based on user-granted permissions. This broad access, while intended to enhance functionality, is precisely what Wardle identifies as the critical risk factor. He explicitly warned against installing Muse, labeling it "trivial to turn Muse into the ultimate backdoor" due to its extensive privileges.
Normally, macOS security features prevent applications from accessing each other's sensitive data, such as microphone input or saved logins. However, by hijacking Muse, an attacker can leverage the legitimate application's permissions to bypass these safeguards. The vulnerability resides in an undocumented setting, endo_voyager_dictation_endpoint, which dictates where Muse sends dictation data. An attacker can modify this preference without requiring additional permissions, redirecting user voice input and associated data to a controlled server.
ClickFix
While the core vulnerability requires malware to already be running on a Mac, Wardle highlighted a method called "ClickFix" through which a remote attacker could achieve this initial compromise. ClickFix is a social engineering technique that tricks users into executing a single command, often pasted into the Terminal, without needing to download or install any software. This makes it a potent vector for delivering the initial payload necessary to exploit the Muse flaw.
Once Muse is compromised, Wardle demonstrated three critical capabilities for an attacker: intercepting user dictation, injecting additional trusted instructions into Muse, and capturing the user's Muse account token. This token allows an attacker to access the user's chat history and directly control the assistant across all devices where the Muse account is signed in, including iPhones. The ability to command smart-home devices or initiate Bluetooth scans through a compromised Muse account illustrates the profound implications of this type of attack, extending beyond the initial Mac compromise.
Key points
- Security researcher Patrick Wardle discovered a vulnerability in Meta's Muse AI assistant for Mac.
- The flaw allows malware already on a Mac to hijack Muse by changing a hidden setting, redirecting user dictation to an attacker.
- Attackers can read dictated prompts, inject commands, and steal the Muse account token, gaining control across multiple devices.
- The vulnerability leverages Muse's broad access permissions, potentially bypassing macOS security features.
- Wardle chose full disclosure to raise user awareness, and Meta has reportedly issued a fix, though details are unconfirmed.
Meta has reportedly pushed out a fix for this vulnerability, which, if confirmed and widely adopted, would significantly mitigate the immediate risk to users. The public disclosure by Patrick Wardle also raises awareness, prompting users to take precautionary measures and encouraging developers to prioritize security in AI assistant design.
The broad access granted to AI assistants like Muse creates a tempting target for attackers, and the difficulty for traditional security software to detect commands originating from a legitimate, signed app like Muse poses a significant challenge. If the fix is not comprehensive or widely implemented, or if users fail to update, the potential for widespread exploitation remains high, turning personal AI agents into persistent backdoors.


