The record
Written from the 1 report below. Nothing here is unsourced.
- A security researcher found a flaw in the macOS version of Meta's Muse AI assistant that allows locally running malware to intercept voice dictation.
- By modifying a hidden preference file, an attacker can redirect audio and text prompts to an unauthorized server.
- The hijacked session enables the attacker to issue commands on behalf of the user across multiple devices.
- This vulnerability highlights the risks of granting broad system access to AI agents.
What to watch next
- Release of a security patch from Meta for the Muse macOS application
- Potential discovery of similar dictation redirection vulnerabilities in other AI-powered desktop applications
Who said what1
Only words found exactly in the article are shown, attributed and linked to the line they came from.
Patrick Wardle
1 quote · 1 outlet
“trivial to turn Muse into the ultimate backdoor.”
In the article
…across their files, email, messages, calendar, shopping and smart-home apps, using whatever access the person chooses to give it. That access is the point, Wardle says. He urged people not to install Muse, calling it " trivial to turn Muse into the ultimate backdoor. " macOS normally prevents one app from accessing another app's files, microphone, camera, or saved logins, so ordinary malware is limited in what it can access. An attacker who can quietly steer Muse instead gets…
Coverage1
All filed from India
Named United States · macOS · Meta · Muse · Apple · Patrick Wardle
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
