A single setting turns a Mac AI assistant into a backdoor

One undocumented setting inside Meta's Mac agent lets any local program point dictated prompts at a server an attacker controls, along with the token that unlocks the account.

AppleThreat Staff
2 Min Read

A single undocumented configuration key has let ordinary programs on a Mac take charge of an AI assistant that holds the keys to a user’s messages, calendar, camera and location.

The opening sits in Muse, the desktop agent Meta pushed out this month. macOS security researcher Patrick Wardle found that any application or terminal command, carrying no special permissions of its own, can rewrite a list of settings the assistant never documents. One entry, endo_voyager_dictation_endpoint, decides which server transcribes a user’s spoken prompts.

Where the audio actually goes

Repointing that value at a machine the attacker controls means the next dictated prompt is delivered there instead of to Meta. The recording arrives with the token that authenticates the account, and that token is enough to operate the agent.

Wardle built proof-of-concept attacks that wrote malicious files to disk, snapped pictures through the camera, and pulled the location of a phone linked to the hijacked account.

The catch and the fix

The intrusion is local, so an attacker still needs a way to run code first. A ClickFix-style lure, which talks a user into pasting a command into Terminal, would be enough. Meta shipped a hotfix more than 12 hours after the finding went public.

Wardle noted that developers have long been able to keep speech recognition on the machine through tools Apple provides, yet Meta chose to route dictation to servers it can log. Separately, Amazon had cut the agent off from its storefront about half a day before the disclosure.

Share This Article