tech π¨ Meta's Muse AI had a sneaky macOS security bug
Security researcher Patrick Wardle found a zero-day vulnerability in Meta's Muse AI desktop client for macOS. The flaw allows unprivileged software to hijack the app by overwriting a debug setting, endo_voyager_dictation_endpoint. This lets attackers reroute audio and steal authentication tokens, enabling prompt injection attacks. The vulnerability bypasses macOS security boundaries because Muse has broad system permissions. Meta deployed a hotfix by removing the internal setting after the public disclosure. π€