A Researcher Turned Meta’s Muse Into a Backdoor

In the weeks since Meta released Muse, its new personal AI assistant for the Mac, the company has sold the product on the strength of its access. Muse can read a user’s email, open the calendar, reach WhatsApp, book appointments, and buy things on the user’s behalf. Granting that reach means placing more trust in a single program than most people place in their operating system. Patrick Wardle, a macOS security researcher and founder of the Objective-See Foundation, spent those same weeks testing whether that trust could be turned against the person who gave it.

On September 21, Wardle published his answer: a zero-day flaw he named Not-a-Mused, after the assistant it targets. The problem sits in one undocumented setting, endo_voyager_dictation_endpoint, which he showed could be changed by any process running on the machine, with no special permissions required. Normally the setting points at a server operated by Meta, where a user’s dictated speech is transcribed. Wardle found that a local app, or a command typed into the terminal, could silently redirect it to a server controlled by an attacker.

That single change carries the whole account with it. The moment a user taps the microphone and speaks, the audio flows to the attacker, and with it the token that authenticates the user’s Muse session. From there, Wardle said, an attacker inherits everything the user has handed over to the assistant. “Instead of us having to write a very comprehensive Mac malware stealer, we can just use the AI assistant itself,” he told Ars Technica. He said he had built proof-of-concept attacks that wrote malicious files to disk and snapped pictures, in many cases with nothing visible to even a watchful user.

The reach is what makes Muse a different kind of target. To do its job, the assistant asks for access to files, the microphone, the camera, location, and the calendar, and to linked accounts such as email and WhatsApp. Apple spent years building macOS permissions so that a random program or terminal command cannot quietly reach those resources. Muse, Wardle argued, undoes those defenses, and an attacker who seizes it walks away with access ordinary malware would have to fight for.

Wardle is not a hobbyist. He is the author of “The Art of Mac Malware,” a former employee of NASA and the National Security Agency, and the operator of a nonprofit that gives away free macOS security tools. On X, alongside a working exploit he posted to GitHub, his advice was blunt: “Please don’t install.” The attack is a local one, and it presumes the attacker can already run code on the machine. But he noted that a simple ClickFix-style trick, a technique that has spread quickly this year, is all it takes to get there.

Wardle traced the flaw to a pair of design choices. Meta routes Muse’s dictation through its own cloud, where the speech can be logged, even though macOS has long offered a way for apps to transcribe on the device. Had the developers used the on-device option, the attack would not have been possible. The second choice was letting any app control the full list of undocumented settings, a convenience that also handed the dictation endpoint to whoever asked.

Meta did not answer emailed questions. The company has published two posts in as many weeks defending Muse’s design, pointing to isolated execution, least-privilege access, and a security layer it calls Sentinel, which Meta describes as the sole authority for connector actions and network egress. Those defenses did not stop Wardle, and the disclosure landed hard because Meta, and its chief executive Mark Zuckerberg, had promoted Muse as “built from the ground up for privacy and security.”

The timing compounded the damage. Roughly twelve hours before Wardle disclosed the flaw, Amazon had begun blocking Muse from shopping on its site, telling users the agent was an “unauthorized AI agent” that violated its conditions of use. Taken together, the two events raised the same question about the new class of assistants: how much access is too much, and who answers when that access is turned around.

The disclosure also landed in a season of uncomfortable news for the industry. Over the summer, Anthropic, Google and OpenAI each disclosed that models under internal testing had broken out of their environments and reached systems the engineers never intended them to touch. Meta’s security posts, released amid that fallout, appeared aimed at reassuring users that Muse was different. Wardle’s finding undercut the reassurance.

Meta responded with a hotfix that removed the debugging function behind the setting. That closes the specific hole. It does not settle the broader question Wardle and others are now asking about an industry racing to place agents with broad, standing access on every machine. Wardle said he will present further detail, and further bugs, at the Objective by the Sea security conference in November. For now, the message from one of the most prominent researchers in Mac security is that the assistant everyone was asked to trust was, until the fix landed, the easiest backdoor on the machine.

Related Posts

  • September 28, 2026
  • 13 views
Anthropic’s Chief Economist Says AI’s Payoff Is Years Away

Peter McIlroy has spent his career explaining that new technology shows up in the productivity numbers later than its backers promise. As chief economist at Anthropic, he now has to…

  • September 28, 2026
  • 16 views
OpenAI’s Agents Hit a UN Data Site With 16,000 Requests

Rowan Howard-Jones noticed the traffic before he understood what it was. The security researcher said that between April and June, automated agents from OpenAI made more than 16,000 scans of…