importantSYS.SOURCE: The Hacker News• 2026-09-22T12:03:57+05:30
Hidden Meta Muse Setting Enables AI Assistant Backdoor via Dictation Hijacking
A hidden setting in Meta's Muse AI assistant on macOS allows attackers to redirect voice dictation to a malicious endpoint, enabling token theft and remote control. The flaw requires existing malware but bypasses macOS security by leveraging Muse's permissions, posing a significant risk to user data and device control.
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.
It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.
The flaw is in
*** END OF TRANSMISSION ***