chiprook
← Security
SecuritySeptember 25, 2026, 21:14

Undocumented Meta Muse Setting Let Attackers Hijack AI Assistant

Researcher Patrick Wardle found that local malware could modify an undocumented Meta Muse preference file, redirect voice dictation to an attacker's endpoint and steal an auth token. The token works across every device signed into the same account, exposing chat history, location tracking and smart-home controls.

Undocumented Meta Muse Setting Let Attackers Hijack AI Assistant
#Meta#MetaMuse
Read next
Security

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Security

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Security

BragJack attacks hijack AI browser agents through malicious extensions

Security

Meta's Muse AI assistant has a serious 0-day vulnerability