Hidden Muse setting lets local malware hijack assistant
🛡️ Security researcher Patrick Wardle demonstrated on September 21 that malware already running on a Mac can change a hidden Muse preference so dictation is sent to an attacker-controlled endpoint instead of Meta. The issue affects the Mac Muse app and requires code execution as the logged-in user; it is not a remote exploit. Wardle warned that this lets attackers leverage the app's granted permissions to access files, messages, and other resources Muse can reach.
