Threat Intelligence

Meta's Muse AI Assistant Can Be Hijacked into a Backdoor on Macs

The Hacker News · 22 Sept 2026
Key Takeaway Businesses using Macs should hold off enabling Meta's Muse assistant with broad app permissions until Meta addresses this hidden vulnerability, and staff should be trained to never run unexpected terminal commands, even if a website or pop-up claims it's needed to fix an issue.

Security researcher Patrick Wardle has released a proof-of-concept showing that malware already running on a Mac can quietly hijack Meta's Muse AI assistant. By changing a hidden, undocumented setting in the app's preferences, an attacker can redirect voice dictation meant for Meta to their own server instead. The flaw requires that an attacker already has code running as the logged-in user, but Wardle notes this could be achieved through a ClickFix trick that tricks a user into running a single command.

Muse is Meta's newly launched personal AI agent, which can be given access to a user's files, email, messages, calendar, shopping and smart-home apps. This wide-ranging access is exactly what makes the flaw dangerous: once an attacker redirects Muse's dictation, they can read what a user says, insert their own instructions that Muse will trust and act on, and steal a login token that grants control of the victim's Muse account and chat history.

Because macOS normally isolates apps from each other's data and permissions, this technique is notable for letting an attacker bypass those protections by riding on an app the user has already trusted. Wardle also warns that security tools may not flag this activity, since the commands appear to come from a legitimate, signed application rather than obvious malware.

Meta Muse macOS security AI assistant risk backdoor vulnerability ClickFix attack

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.