Back to Newsroom
Threat Intel

A Hidden Setting in Meta's Muse Could Let Attackers Hijack the AI Assistant on Mac

A security researcher has shown how a single undocumented setting in Meta's Muse assistant for Mac can be flipped by any program already running on the device, redirecting the user's spoken prompts to an attacker and handing over the token that controls the account.

A Hidden Setting in Meta's Muse Could Let Attackers Hijack the AI Assistant on Mac

A single hidden setting in Meta's new Muse AI assistant for Mac can be silently flipped to turn the app into a backdoor — no exploit chain needed, just code already running on the machine.

What happened

Independent security researcher Patrick Wardle published a proof-of-concept on September 21 showing that the Mac version of Muse, Meta's personal AI agent launched this month in the US, stores an undocumented preference that decides where the app sends a user's dictated prompts. Any program running as the logged-in user — no special permissions required — can quietly repoint that setting to an address the attacker controls.

Once that's done, when the user taps the microphone and speaks to Muse, the audio and transcribed text go to the attacker's own listening process instead of Meta's servers. From there, Wardle demonstrated that an attacker can read what was dictated, slip in extra instructions that Muse will treat as trusted user input, and capture the authentication token that signs into the victim's Muse account.

Because that account can stay signed in across multiple devices, a stolen token lets an attacker issue commands to Muse anywhere it's active — not just the compromised Mac. In testing, Wardle used a hijacked session to pull a device's exact location, trigger a Bluetooth scan of nearby hardware, and enumerate which smart-home commands the assistant could send. The assistant stopped short of sending messages on its own, only drafting them.

Wardle also flagged a detection gap: because the commands appear to come from Muse itself — a normal, signed Meta app — security software is unlikely to flag them as malicious.

What it doesn't do

The flaw does not bypass macOS's own protections against one app reading another's stored passwords, files, camera, or microphone; it works within whatever access Muse already has. It also doesn't implicate the isolated cloud backend Meta built to keep each user's Muse data separated — the weak point sits in the Mac client's dictation handling, which Wardle says Meta built in-house instead of routing through Apple's built-in dictation.

Wardle went straight to public disclosure rather than a private report to Meta, arguing it's often the fastest route to a fix. Meta has since pointed to a change posted on X as a resolution; at the time of writing, what that change addresses hasn't been independently confirmed, and Meta has not issued a security advisory. Wardle says he has additional, unreported flaws in other widely used AI assistants that he plans to detail at the Objective by the Sea conference in Hawaii this November.

What to do now

Until Meta confirms and documents a fix, Mac users running Muse should:

  • Quit or remove the Muse app if it isn't needed.
  • Review which apps and permissions Muse holds, and revoke anything it doesn't use.
  • Avoid Muse's voice/dictation input for now — the attack depends on it.
  • Treat the Muse account and any connected accounts as exposed if the Mac may already be compromised, and rotate those passwords.
  • Never paste a command into Terminal because a website or message told you to — that's a classic ClickFix-style trick, not a legitimate fix.
SHARE
4Tify — Hidden Muse Setting Turns Meta's AI Into a Backdoor