Ethics & SecuritySeptember 25, 2026
17
🌱

Meta's Muse Agent: Wide-Open Backdoor on Mac

Meta's Muse app could be hijacked via the ClickFix method, prompting security researcher Wardle to warn against installing it.

#Meta#macOS#Security#AI Agent#ClickFix
Metas Muse-Agent: Offene Hintertür auf dem Mac
Share Article
🔥 What happened Security researcher Patrick Wardle hijacked Meta's macOS AI agent Muse via a ClickFix attack, exploiting an undocumented function called endo_voyager_dictation_endpoint. Meta has since removed the feature but denies it was a remote exploit. 💡 Why it matters The app touches emails, calendars, mic, and camera — Wardle found over 50 commands attackers could use to leak audio, trigger prompt injections, or steal auth tokens. Amazon blocked Muse from its store shortly after launch. ⚡ Our take Giving an AI agent full system access and shipping an undocumented debug endpoint isn't a security bug — it's a security philosophy. Meta should kill Muse, not patch it.
The title, summary and analysis of this item were produced automatically by an AI system and have not been editorially reviewed. They may contain errors, bias or omissions — when in doubt, read the linked original source.