Key points
- Patrick Wardle has published proof-of-concept code for a zero-day, dubbed “not-a-mused”, that can turn Meta’s Muse AI assistant into a backdoor.
- An undocumented setting, endo_voyager_dictation_endpoint, can be altered by any local process to redirect dictated audio to an attacker’s server.
- Because Muse holds broad access to files, microphone, camera, location, calendar and even linked iPhones, a compromise could hand an attacker the same reach.
A prominent macOS security researcher has urged Mac users not to install Meta’s new Muse AI assistant, publishing proof-of-concept code for what he described as a zero-day that can turn the app into a ready-made backdoor.
Patrick Wardle, founder of the Objective-See Foundation and author of The Art of Mac Malware, disclosed the flaw in a thread on X accompanied by a working exploit on GitHub.
“Please don’t install,” he wrote. “It’s trivial to turn Muse into the ultimate backdoor.”
Wardle called the flaw “not-a-mused”.
The problem centres on an undocumented Muse setting, endo_voyager_dictation_endpoint, which Wardle showed could be changed by any local process without elevated privileges.
Once that endpoint is redirected, the audio a user dictates to Muse is sent to an attacker’s server instead of Meta’s, which the accompanying code says can allow captured prompts, prompt injection into the assistant, and enable theft of its authentication material.
The trigger is mundane, requiring only that a user click the microphone and dictate a prompt as they normally would.
Wardle said the proof of concept is a local attack, one that assumes an attacker can already run code on the machine as the user.
He argues that Muse is a disproportionately valuable target rather than an ordinary one, because an assistant built to manage a Mac holds far broader access than typical malware would arrive with.
To function, Muse asks for reach across files, microphone, camera, location and calendar, so an attacker who hijacks it inherits everything the user has entrusted to it.
“Muse’s access can potentially become the attacker’s access,” the exploit’s documentation stated.
A follow-up post extended the concern to linked mobile devices, showing categories of actions that could be requested through a compromised session, including retrieving an iPhone’s location, scanning for nearby Bluetooth devices, and accessing information such as contacts, calendars and reminders.
And once a Mac is exploited, you can interact with any of the users “connected” devices also running Muse.
…meaning you remotely task their mobile (iOS) Muse client …invisibly
What can you do? Welll, some very neat iOS stuff! https://t.co/1vr885BCmt pic.twitter.com/x9MCF5QoPR
— Patrick Wardle (@patrickwardle) September 21, 2026
Messaging, by contrast, only prepared a draft rather than sending silently.
Wardle said he would share further detail and further bugs at the Objective by the Sea security conference in November.
Meta has made much of Muse’s security, with company founder Mark Zuckerberg promoting the AI assistant as a personal agent that works around the clock on a user’s behalf.
The social media giant said the system uses isolated execution, least-privilege access, and a dedicated security layer called Sentinel which Meta described as the sole authority for connector actions, and network egress.
Earlier this year, the viral OpenClaw, then known as Clawdbot, prompted warnings from companies and security researchers over the risks of giving an AI agent broad access to a user’s computer, files and accounts.

