Undocumented Meta Muse Setting Let Attackers Hijack AI Assistant
Researcher Patrick Wardle found that local malware could modify an undocumented Meta Muse preference file, redirect voice dictation to an attacker's endpoint and steal an auth token. The token works across every device signed into the same account, exposing chat history, location tracking and smart-home controls.
- No zero-day needed: local write access to a config file was enough
- Stolen token grants access on every device tied to the account
- Chat history, location tracking and smart-home control are exposed
- No patch or vendor disclosure for Meta Muse is mentioned
Read next
Security