Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

Imported from official source

Cybersecurity Classified by Officially

Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.”

Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars.

To do that, they need more permissions, account connections, and sensitive data. So, when Meta promised that “Muse is built from the ground up for privacy and security,” we did not expect an AI agent that can easily be manipulated into handing all that access to an attacker.

Meta says Muse can handle appointments, forms, customer-service interactions, purchases, document creation, and connections to services such as WhatsApp, email, calendars, and social platforms. It may also receive macOS permissions to access protected resources, including files, the microphone, camera, location, and calendars.

According to Ars Technica, Wardle found that a locally running application or terminal command could alter an undocumented Muse configuration setting that controls the server used for dictation transcription. By redirecting dictation traffic to an attacker-controlled server, an attacker could capture voice prompts and obtain the authentication token for the victim’s Muse account.

This is not a remote-code-execution vulnerability that can compromise an otherwise clean Mac. The attacker first needs a way to run code locally, such as through malware, a malicious application, or social engineering.

But as we have seen with infostealer malware finding its way onto Macs, that initial access is far from impossible.

Someone’s watching your accounts. Make sure it’s us.

PROTECT YOUR IDENTITY

This is an extract. The publication continues at the source.

Read the original at the source: https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-that-can-turn-it-into-a-mac-backdoor

Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Malwarebytes — imported from official source
Official source
https://www.malwarebytes.com/blog/feed/index.xml RSS
Imported
September 22, 2026 11:30
Versions
1 recorded
Identity
https://www.malwarebytes.com/blog/bugs/2026/09/metas-muse-ai-assistant-has-a-zero-day-t...

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.