Meta Muse AI app flaw lets local malware redirect dictation traffic
A security researcher has identified a possible local zero-day flaw in Meta’s Muse macOS AI app, allowing unprivileged malware already running on a computer to redirect dictation traffic. The issue could expose users’ dictated audio and prompts, enable prompt injection or theft of authentication data, and misuse permissions granted to Muse, undermining Meta’s claims about user control.
The vulnerability involves an undocumented setting that determines Muse’s dictation endpoint and can be changed without special privileges. It cannot be exploited remotely, but effectively gives local malware broader access, particularly because AI applications may have extensive access to data and system tools; Meta had not responded to requests for comment.
- Local malware can redirect Muse dictation traffic.
- Dictated audio, prompts and credentials could be exposed.
- The flaw highlights risks from AI apps with broad permissions.