VMTech
Discuss a project

Mac Muse Dictation Setting Can Be Abused by Local Malware

Mac Muse Dictation Setting Can Be Abused by Local Malware

Security researcher Patrick Wardle has demonstrated that malware already running under a logged-in macOS user account can redirect dictation in Meta Muse, the personal AI agent Meta launched in the United States this month. The proof of concept, released on September 21, changes an undocumented Mac preference named endo_voyager_dictation_endpoint so spoken prompts are sent to an attacker-controlled endpoint rather than Meta.

The finding concerns the Mac version of Muse and is not a remote entry point into a Mac. An attacker must first be able to execute code as the logged-in user. But once that condition is met, the altered setting can let the attacker use the permissions that the Muse owner has already granted to the assistant.

A dictation route that can be changed silently

Wardle found that any program running as the logged-in user can modify the endpoint preference without requesting additional permissions. When the Muse user taps the microphone and dictates a prompt, both the audio and text can then be delivered to a small program running locally on the Mac instead of to Meta.

In his demonstration, that intermediary could read the dictated content, insert additional instructions that Muse would trust and act on, and capture the token identifying the user’s Muse session. The technique does not extract passwords or saved login tokens protected by macOS app isolation. Instead, it makes the signed-in Muse application act with the access already assigned to it.

Broad agent permissions raise the impact

Muse can work across files, email, messages, calendars, shopping and smart-home applications, depending on the permissions selected by its owner. macOS ordinarily restricts one application from directly reaching another application’s files, microphone, camera or stored credentials. Steering Muse offers a route around those limits because commands originate from a legitimate, signed application.

Wardle warned that security tools may therefore have difficulty distinguishing malicious activity from normal Muse operations. In tests, a stolen session was used to direct Muse on an iPhone signed into the same account to report its exact location, scan nearby Bluetooth devices and list available smart-home commands. Muse drafted messages in those tests rather than sending them independently.

The cloud architecture is not the affected component

Meta designed Muse to operate in a separate cloud environment intended to isolate each user’s agent and to apply a checking layer to proposed actions. Wardle’s finding does not show a break in that cloud isolation. The weakness is in the Mac client’s custom dictation handling, which he contrasts with Apple’s on-device dictation.

There is no patch available in the reported scenario. Users can quit or remove Muse until Meta addresses the issue, avoid its voice input, and review or revoke permissions the assistant does not require. If a Mac is suspected to be compromised, connected accounts should be treated as exposed and their passwords changed. For businesses evaluating AI agents, the practical implication is to minimize delegated permissions and account sessions, because a locally compromised endpoint can turn an assistant’s approved access into the attacker’s operating channel.

#cybersecurity#macossecurity#aiagents#endpointsecurity
Open analytics
On the site 0 views
min read 4 22.09.2026
Instagram

Mac Muse Dictation Setting Can Be Abused by Local Malware

Open the post on Instagram ↗