Security researcher says don’t install Meta’s Muse AI assistant

Key points

Patrick Wardle has published proof-of-concept code for a zero-day, dubbed “not-a-mused”, that can turn Meta’s Muse AI assistant into a backdoor.

Security researcher says don't install Meta's Muse AI assistant

Security researcher says don't install Meta's Muse AI assistant

Key points

  • Patrick Wardle has published proof-of-concept code for a zero-day, dubbed “not-a-mused”, that can turn Meta’s Muse AI assistant into a backdoor.
  • An undocumented setting, endo_voyager_dictation_endpoint, can be altered by any local process to redirect dictated audio to an attacker’s server.
  • Because Muse holds broad access to files, microphone, camera, location, calendar and even linked iPhones, a compromise could hand an attacker the same reach.




Security researcher says don't install Meta's Muse AI assistant










A prominent macOS security researcher has urged Mac users not to install Meta’s new Muse AI assistant, publishing proof-of-concept code for what he described as a zero-day that can turn the app into a ready-made backdoor.

Patrick Wardle, founder of the Objective-See Foundation and author of The Art of Mac Malware, disclosed the flaw in a thread on X accompanied by a working exploit on GitHub.

“Please don’t install,” he wrote. “It’s trivial to turn Muse into the ultimate backdoor.”

Wardle called the flaw “not-a-mused”.

The problem centres on an undocumented Muse setting, endo_voyager_dictation_endpoint, which Wardle showed could be changed by any local process without elevated privileges.

Once that endpoint is redirected, the audio a user dictates to Muse is sent to an attacker’s server instead of Meta’s, which the accompanying code says can allow captured prompts, prompt injection into the assistant, and enable theft of its authentication material.

The trigger is mundane, requiring only that a user click the microphone and dictate a prompt as they normally would.

Wardle said the proof of concept is a local attack, one that assumes an attacker can already run code on the machine as the user.

He argues that Muse is a disproportionately valuable target rather than an ordinary one, because an assistant built to manage a Mac holds far broader access than typical malware would arrive with.

To function, Muse asks for reach across files, microphone, camera, location and calendar, so an attacker who hijacks it inherits everything the user has entrusted to it.

“Muse’s access can potentially become the attacker’s access,” the exploit’s documentation stated.

A follow-up post extended the concern to linked mobile devices, showing categories of actions that could be requested through a compromised session, including retrieving an iPhone’s location, scanning for nearby Bluetooth devices, and accessing information such as contacts, calendars and reminders.

Messaging, by contrast, only prepared a draft rather than sending silently.

Wardle said he would share further detail and further bugs at the Objective by the Sea security conference in November.

Meta has made much of Muse’s security, with company founder Mark Zuckerberg promoting the AI assistant as a personal agent that works around the clock on a user’s behalf.

The social media giant said the system uses isolated execution, least-privilege access, and a dedicated security layer called Sentinel which Meta described as the sole authority for connector actions, and network egress.

Earlier this year, the viral OpenClaw, then known as Clawdbot, prompted warnings from companies and security researchers over the risks of giving an AI agent broad access to a user’s computer, files and accounts.



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.