One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Summary
A security researcher discovered that malware already running on a Mac can hijack Meta's Muse AI assistant by changing a hidden setting (endo_voyager_dictation_endpoint) that redirects voice commands to the attacker instead of Meta, allowing the attacker to steal the user's Muse account token and access everything the app is permitted to do. The attack only works if malware is already running on the device as the logged-in user, but an attacker could deliver that malware using a ClickFix trick (a social engineering technique that tricks users into running commands). Once compromised, the attacker gains broad access to the user's files, email, messages, calendar, and smart-home controls that Muse was granted permission to use.
Solution / Mitigation
According to the source, Meta has "pushed out what he called a 'fix'" but The Hacker News could not confirm what the change does and Meta has not published a security advisory. Until Meta confirms a fix, Mac users can: (1) Quit Muse or remove it entirely; (2) Review the apps and permissions Muse holds and revoke any it does not need; (3) If the Mac may already be compromised, treat the Muse account and connected accounts as exposed and change their passwords; (4) Avoid using Muse's voice input feature, which the attack relies on.
Classification
Affected Vendors
Related Issues
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
CVE-2026-24747: PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `wei
Original source: https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html
First tracked: September 22, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%