Security News

Researcher Warns Against Installing Meta's Muse AI Assistant on Mac

iTnews · 22 Sept 2026
Key Takeaway Small businesses should avoid installing Meta's Muse AI assistant on company Macs until Meta confirms the flaw is fixed, and should review what device permissions any AI assistant apps have been granted.

Patrick Wardle, founder of the Objective-See Foundation, has publicly warned Mac users against installing Meta's new Muse AI assistant after discovering a flaw he says turns the app into what he calls "the ultimate backdoor." The issue lies in an undocumented setting that controls where dictated audio is sent. Wardle demonstrated that any local process, without special privileges, can redirect this setting so a user's spoken prompts go to an attacker's server instead of Meta's.

The attack requires an attacker to already have some code running on the victim's machine, and is triggered simply by a user dictating a prompt as normal. Because Muse is designed to manage broad parts of a Mac, including files, microphone, camera, location and calendar, Wardle argues it is a far more valuable target than typical malware, since hijacking it can hand an attacker everything the user has granted the assistant access to. He also showed that a compromised Muse session on a Mac could be used to remotely interact with a linked iPhone, retrieving location data, scanning for nearby Bluetooth devices, and accessing contacts, calendars and reminders.

Wardle says he plans to share further details and additional bugs at the Objective by the Sea security conference in November.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from iTnews. We link back to every original so you can read it yourself.