What Happened
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in
Why It Matters
A proof of concept reportedly shows that malware already running on a Mac can modify a hidden Meta Muse setting so dictated prompts are redirected to an attacker instead of Meta, potentially exposing prompts and enabling misuse of access granted to the assistant. The reported issue involves unauthorized control of an AI assistant through local malware rather than prompt injection. RealGround analysis: security testing should validate assistant configuration integrity, local privilege boundaries, microphone and data-routing controls, and detection or recovery mechanisms for tampering.
RealGround Analysis
This signal maps to AI agent abuse. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.
Recommended Actions
- Restrict AI agent tool permissions and production write paths.
- Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
- Add human approval workflows for high-impact or state-changing actions.
- Run prompt injection and indirect prompt injection tests against affected workflows.
- Document the owner, control gap, and remediation deadline for this risk class.
Source
https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html
