Meta’s Muse AI assistant reportedly patched after Mac hijacking flaw
A post credits security researcher Patrick Wardle with finding a flaw that could let a local script redirect voice dictation and steal a Muse user’s authentication token.
TLDR
A post describing Wardle’s discovery says a local script or terminal command could silently alter the Muse Mac app’s hidden configuration. It claims that changing the voice-dictation endpoint could let an attacker steal an authentication token and gain control over everything Muse can access. A separate post describes the vulnerability as potentially allowing a Mac hijack and relays Meta’s statement that it has issued a fix.