Image: Malwarebytes Labs
Mac users should avoid installing Meta’s Muse AI assistant for now after a researcher found that software already running on the Mac could redirect its dictation traffic. The weakness is not a drive-by attack: an attacker must first get malware, a malicious app or a command running locally.
What could be exposed
As reported by Malwarebytes Labs, Wardle found that a local app or Terminal command could change an undocumented Muse setting that chooses the server used to transcribe dictation.Redirecting that traffic to an attacker-controlled server could expose spoken prompts and the authentication token for the victim’s Muse account. An authentication token is a digital credential that keeps a user signed in.
The potential impact is wider than leaked dictation because Meta says Muse can interact with email, calendars, WhatsApp and other services. It may also receive macOS access to protected resources such as files, the microphone, camera, location and calendars.
Local access is required first
This finding does not let someone remotely compromise an otherwise clean Mac by itself. The attacker must already be able to execute code locally, potentially through malware, a malicious application or social engineering.Once that foothold exists, compromising an authenticated AI agent could give an attacker a simpler route to several connected services and Mac permissions. Traditional information-stealing malware would otherwise have to find browser data, credentials, documents and chats separately.
Steps for Mac users
- Do not install Muse while this issue remains unresolved; if it is already installed, avoid using it with sensitive accounts or broad macOS permissions.
- Review AI-agent connections and remove access to email, chats, calendars, cloud storage, payments or device features that the agent does not need.
- Keep macOS and other software updated, and use current real-time anti-malware protection.
- Do not run Terminal commands copied from websites or unsolicited messages. This helps prevent ClickFix attacks, which trick people into infecting their own devices by following fake repair or verification steps.