Meta Muse Mac hidden dictation endpoint security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A hidden dictation setting in Meta's Muse assistant for Mac lets malware already running as the logged-in user redirect prompts away from Meta and toward an attacker-controlled destination. The flaw can expose dictated input, inject trusted instructions, and steal the Muse session token, turning the assistant into a backdoor on a compromised Mac. No patch was available at publication, leaving Muse on macOS exposed until Meta fixes the undocumented setting.
Related Happenings
WebKit memory corruption, out-of-bounds write, and use-after-free flaws (multiple vulnerabilities)
Vulnerability
H score1
First: 30.06.2026 10:15
Last: 30.06.2026 10:15
Sources 1
About this happening:
WebKit now has four patched vulnerabilities, including CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, that can be triggered by malicious...
WebKit memory corruption, out-of-bounds write, and use-after-free flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: WebKit now has four patched vulnerabilities, including CVE-2026-43707, CVE-2026-43716, CVE-2026-43745, and CVE-2026-43715, that can be triggered by malicious...
MacOS XPC cached signature trust privilege escalation privilege-escalation flaw
Vulnerability
H score23
First: 25.06.2026 14:00
Last: 25.06.2026 14:00
Sources 1
About this happening:
macOS XPC trusted software verification lets a non-root user abuse cached signature trust to call privileged helper functions without authentication, opening a route to ...
MacOS XPC cached signature trust privilege escalation privilege-escalation flaw
VulnerabilityAbout this happening: macOS XPC trusted software verification lets a non-root user abuse cached signature trust to call privileged helper functions without authentication, opening a route to ...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
Vulnerability
H score24
First: 18.06.2026 15:23
Last: 18.06.2026 15:23
Sources 1
About this happening:
Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
Beats Studio Buds Bluetooth BR/EDR missing-authentication security flaw (multiple vulnerabilities)
VulnerabilityAbout this happening: Beats Studio Buds are affected by CVE-2025-20701, a missing-authentication flaw in Airoha system-on-a-chip (SoCs) and the Bluetooth BR/EDR radio that can let a...
AUDIOFIX and MiniRAT macOS malware activity
Malware Activity
H score34
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
AUDIOFIX and MiniRAT macOS malware activity
Malware ActivityAbout this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical Analysis
H score33
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical AnalysisAbout this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Timeline
-
22.09.2026 09:33 2 articles · 0h ago
Proof-of-concept shows Meta Muse for Mac can be redirected through a hidden dictation endpoint
Initial DisclosureSecurity researcher Patrick Wardle released a proof-of-concept showing that malware already running as the logged-in user can change the undocumented endo_voyager_dictation_endpoint preference in Meta's Muse for Mac, redirecting microphone dictation away from Meta and toward an attacker-controlled endpoint. Wardle said an attacker can read what the user dictated, add extra instructions that Muse trusts and acts on, and steal the Muse session token to control the assistant directly.
Show sources
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor — thehackernews.com — 22.09.2026 09:33
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor — thehackernews.com — 22.09.2026 09:33
-
22.09.2026 09:33 1 articles · 0h ago
Mac users are told to quit or remove Muse and avoid voice input until Meta fixes the flaw
Mitigation Patch UpdateMac users are advised to quit or remove Muse, review and revoke unnecessary permissions, avoid voice input, and change passwords for connected accounts if the Mac may already be compromised. The guidance closes the path shown by the hidden dictation redirection and reduces what a local attacker can access through the app.
Show sources
- One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor — thehackernews.com — 22.09.2026 09:33