Meta Muse Mac App Flaw Could Expose AI Assistant Access Through Hidden Setting

Meta Muse Mac App Flaw Could Expose AI Assistant Access Through Hidden Setting

Security researcher Patrick Wardle has demonstrated a flaw in the Mac version of Meta’s Muse AI assistant that could allow malware already running on a device to redirect user dictation and misuse the permissions granted to the application. In a proof of concept published on September 21, Wardle showed that an attacker with existing code execution on a Mac could modify a hidden Muse setting and cause voice prompts recorded through the application to be sent to an attacker controlled destination instead of Meta. The issue does not allow attackers to compromise a Mac remotely on its own because the device must already be running malicious code under the logged in user account. However, Wardle said a remote attacker could potentially gain access through social engineering techniques such as ClickFix, where users are persuaded to run a command without downloading or installing additional software. Meta launched Muse as a personal AI agent in the United States, allowing users to connect it with files, emails, messages, calendars, shopping services, and smart home applications depending on the permissions they provide.

Wardle explained that the risk comes from the broad access users grant AI assistants rather than from a direct break into macOS security protections. Normally, macOS restricts applications from accessing data belonging to other apps, including files, microphones, cameras, and saved credentials. However, an attacker who can manipulate Muse may be able to use the permissions already approved by the user. According to Wardle’s research, the undocumented preference setting named endo_voyager_dictation_endpoint controls where Muse sends dictation data. Any application running with the same user’s privileges can modify this setting and redirect voice input toward an attacker controlled service without requiring additional permissions. Once redirected, the dictated audio and text can be received by a local program controlled by the attacker. Wardle demonstrated several possible actions through the proof of concept, including reading user dictated content, injecting additional instructions that Muse may process, and capturing a token associated with the user’s Muse account.

The researcher said access to the Muse token could allow an attacker to interact with the user’s assistant account across multiple devices where the account is active. During testing, Wardle demonstrated controlling Muse on an iPhone by instructing it to provide the device’s location, perform a Bluetooth scan of nearby devices, and identify available smart home commands. He noted that in his demonstrations, Muse generated message drafts instead of independently sending messages. Wardle also clarified that the technique does not bypass macOS protections designed to prevent applications from accessing other apps’ stored passwords and authentication data. Instead, the attack relies on Muse providing its own token and performing actions using access that the user had already approved. He also stated that the research does not indicate any compromise of Meta’s cloud infrastructure, which was designed to separate user agents and protect individual user data. Wardle said he did not submit the issue to Meta before publishing his research, choosing full disclosure to highlight the risk to users and encourage faster response. He later said Meta had released what he described as a fix through a post on X, although a detailed security advisory from Meta was not available at the time of reporting.

Until additional details about the fix are confirmed, Mac users can reduce exposure by limiting Muse permissions, removing the application if they do not need it, and reviewing connected accounts for unnecessary access. Users who believe their Mac may already be compromised should consider their Muse account and connected services potentially exposed and update their passwords. Avoiding Muse voice input can also prevent the specific attack method demonstrated by Wardle because the technique depends on redirected dictation. Users should also avoid running commands copied from websites, messages, or unexpected prompts in Terminal, as this is a common method used in ClickFix style attacks. Meta has highlighted security as an important part of Muse’s design, including a separate cloud system intended to isolate user data and an approval layer for assistant actions. Wardle said the issue exists within the Mac application itself and relates to Muse’s custom dictation handling approach rather than its cloud security model. He added that he has identified additional security issues in other AI assistants and plans to present further research at the Objective by the Sea conference in Hawaii in November.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment