<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Meta Patched a Flaw That Let Attackers Hijack Its AI Agent

A hidden setting in Meta's Muse for Mac let local malware redirect dictation, read prompts, and steal the session token. Meta shipped a fix in 16 hours.
Content Team

Patrick Wardle, founder of Objective-See, disclosed a zero-day in Meta's Muse, a macOS AI assistant Meta markets around a dedicated secure VM, protected credential storage, and user-controlled permissions. An undocumented preference called endo_voyager_dictation_endpoint can be rewritten by any process running as the logged-in user, redirecting Muse's dictation traffic to an attacker-controlled server.

From there an attacker reads dictated prompts and audio, injects instructions Muse trusts and acts on, and lifts the Muse session token. Wardle's proof-of-concept, not-a-mused, used a stolen token to make the Muse app on his iPhone report precise location, run Bluetooth scans, and list smart-home commands. No CVE or CVSS has been assigned, and no in-the-wild exploitation has been reported.

Exploitation needs code execution as the user first, so existing malware is the delivery route rather than a remote attack. Meta shipped a hot-fix roughly 16 hours after Wardle went public on September 21, and he confirmed it the next day. If you ran Muse before the fix, update it, revoke unnecessary permissions, and treat connected accounts as exposed.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo