Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

← Back to the feed

Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

Ars Technica · 1 hour ago

Meta's new AI assistant Muse contains a serious zero-day security vulnerability that undermines the company's claims about its privacy and security. Despite CEO Mark Zuckerberg's assertions that the tool was "built from the ground up for privacy and security," the flaw allows any locally installed application or terminal command to gain complete control of the assistant. The discovery is significant because Muse has extraordinarily broad permissions—including access to authentication tokens, the ability to make purchases, generate images, access cameras and microphones, and monitor calendars and location data.

The vulnerability, discovered by macOS security researcher Patrick Wardle, exploits a design flaw that allows any app to modify undocumented settings, including the endpoint for audio transcription. By redirecting the transcription endpoint to a malicious server, attackers can intercept the authentication token that grants complete control over a user's Muse account. Wardle has developed proof-of-concept attacks demonstrating the exploit can write malicious files to disk and activate cameras without alerting users. The discovery has prompted swift action from Amazon, which began blocking Muse from its platform, whilst Meta has declined to publicly address the security concerns.

  • Meta's Muse has zero-day vulnerability allowing local apps to hijack the assistant
  • Attackers can steal authentication tokens and control user accounts completely
  • Flaw stems from poor design decisions about transcription and app permissions

AI Americas Technology World

Read the full article at the source →