Hacker News
A Muse macOS Zero-Day Lets Any Local Process Redirect the Agent's Dictation to an Attacker's Server
Patrick Wardle of Objective-See disclosed on September 21 that Meta's Muse macOS app exposes an undocumented setting, endo_voyager_dictation_endpoint, which an unprivileged local process can rewrite without elevated permissions, redirecting dictated audio and prompts to attacker infrastructure along with Muse authentication material. He shipped a proof of concept named not-a-mused. This is not remote code execution on a clean Mac, and Wardle's actual argument is the one builders should take: ordinary malware boxed in by macOS privacy controls can escalate by borrowing the broad authority a user already granted an agent, and no patch or advisory had appeared as of September 22.
Source
↳ Follow the thread