On September 25, Meta was reported to be adding a clearer safety warning inside Muse after a vulnerability was identified in the assistant’s macOS app. The reported flaw could let local software redirect voice transcription and potentially expose a Muse account token. Meta separately said it had released a hotfix.

How the Muse vulnerability could work

Researcher Patrick Wardle identified a flaw that reportedly allowed locally running apps or commands to change undocumented Muse settings, regardless of their macOS permissions. One of those settings controlled the endpoint—the server address that receives voice transcription.

If local code redirected transcription to a server controlled by an attacker, it could expose the token used to authenticate a Muse account. That token could then allow the attacker to control the account. A described route involved social engineering that could persuade a user to run a command locally.

The reported weakness was in Muse’s macOS app and its handling of those settings.

What the proof-of-concept attacks could do

Wardle said proof-of-concept attacks could write malicious files and take pictures. He said some actions could happen without an indication that would alert even an attentive user.

A proof of concept demonstrates a possible attack path. It is not, by itself, evidence that the attack was used against real users.

Meta’s reported response

Meta said it had released a hotfix for the vulnerability. Separately, the September 25 report said the company was adding a clearer safety warning inside Muse.