Hidden Meta Muse Dictation Setting Can Turn the AI Assistant Into a Mac Backdoor, Researcher's PoC Shows
Patrick Wardle's September 21 PoC shows Mac malware already running as the logged-in user can retarget Muse dictation, read prompts, inject instructions, and steal the session token; no patch is available.
Mac security researcher Patrick Wardle released a September 21 proof-of-concept showing that malware already running as the logged-in Mac user can abuse an undocumented Meta Muse preference, endo_voyager_dictation_endpoint, which selects the dictation transcription endpoint. Because the setting can be changed by a local process without extra permissions, dictated audio and text can be redirected to an attacker-controlled destination — The Hacker News describes an attacker-controlled local program, while Malwarebytes describes an attacker-controlled server. The attacker can read voice prompts, append instructions that Muse acts on, and capture the victim's Muse authentication token. Wardle demonstrated that a stolen token, reused on an iPhone, let him direct Muse to report its location, run a Bluetooth scan, and list smart-home commands; messages were only drafted, not sent. Malwarebytes notes the issue concentrates risk because Muse may hold macOS permissions and links to WhatsApp, email, calendars, and other services that an infostealer would otherwise have to collect separately. The flaw is not remote code execution: the attacker needs prior local code execution via malware or social engineering, and the PoC does not bypass macOS password isolation or Meta's cloud separation. Malwarebytes characterizes the flaw as a zero-day; The Hacker News does not. No patch is available, and Wardle advised users not to install the Muse assistant.
- Researcher: Patrick Wardle; proof-of-concept published September 21 (reports dated 2026-09-22).
- Undocumented preference endo_voyager_dictation_endpoint selects the Muse dictation transcription endpoint and can be changed by a local process without extra permissions.
- Redirected dictation exposes voice prompts and the Muse authentication/session token; the attacker can also append instructions that Muse acts on.
- A stolen token used on an iPhone let Wardle direct Muse to report its location, run a Bluetooth scan, and list smart-home commands; messages were only drafted.
- Requires prior local code execution as the logged-in Mac user; it is not remote code execution and does not bypass macOS password isolation or Meta's cloud separation.
- Muse concentrates access: it may hold macOS permissions and links to WhatsApp, email, calendars, and other services.
- No patch is available; Wardle advised users not to install the Muse assistant.
- Sources disagree on characterization: Malwarebytes calls it a local zero-day and an attacker-controlled server; The Hacker News does not use the term zero-day and describes an attacker-controlled local program.
Coverage timelineoldest first · each row is one article
- · 5d agoOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
The Hacker News· 67
Patrick Wardle's PoC shows local Mac malware can redirect Meta Muse dictation and hijack granted access.
- · 4d agoMeta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
Malwarebytes Labs· 62
Patrick Wardle says a local zero-day can redirect Meta Muse dictation traffic and steal its account token.