
What if the AI helper you hired to make your life easier actually handed hackers the master key to your entire computer? Meta promised its new Mac-exclusive assistant, Muse, was built from the ground up for privacy and security while managing your emails, calendar, and WhatsApp messages. But just weeks after launch, a major zero-day flaw proved that granting an AI agent—like Meta’s Muse—deep system privileges can quickly backfire, turning Meta’s flag-bearer tool into the ultimate Mac backdoor.
The exploit was uncovered by prominent macOS security researcher Patrick Wardle, founder of the Objective-See Foundation. He dubbed “not-a-mused” the vulnerability that allows a simple terminal command or local process to hijack your entire Muse account and control every sensitive app connected to it.
How a dictation setting turns Muse into a backdoor
The core problem stems from how Muse processes voice commands. Unlike Apple, which handles transcription locally on the Mac, Meta routes voice audio to cloud servers. Wardle discovered that an undocumented preference setting called endo_voyager_dictation_endpoint can be easily modified by any app or script running under the user’s account, without triggering special macOS permission alerts.
By pointing that setting toward a server under the attacker’s control, hackers can intercept dictated voice prompts along with the user’s account authentication token. Once an attacker grabs that token, they gain full control over Muse. Instead of building complex malware to scrape files or capture photos, attackers can simply instruct the already-authenticated AI assistant to do the dirty work for them using its existing system permissions (via Ars Technica).
Amazon blocks Muse as Meta pushes out a hotfix
This security revelation arrives right as tech platforms start pushing back against autonomous agents. Amazon recently began blocking Muse from placing automated orders on its platform. They stated that the AI agent violated its terms of use by making purchases without identifying itself or coordinating with service providers.
Triggering the exploit doesn’t require complex hacking either. Wardle demonstrated that basic social engineering, like a ClickFix trick prompting users to paste terminal commands, provides all the initial access needed. Following public disclosure, David Singleton at Meta Superintelligence Labs confirmed that the company released a hotfix removing the debug dictation setting to close the vulnerability.
The post Meta’s Muse AI Assistant Hit by Serious Mac Zero-Day Vulnerability: The “Not-a-Mused” Exploit appeared first on Android Headlines.


https://t.co/2R7hc9JzyR