Meta patches Muse exploit that let attackers control the AI agent
Summary
Meta has issued a patch for a zero-day vulnerability in its Muse macOS app, discovered by security researcher Patrick Wardle. The exploit utilized an undocumented Muse setting that allowed attackers with local code execution to redirect transcription processing from Meta's servers to their own endpoint, gaining access to the Muse account. Design flaws including cloud-based dictation instead of on-device processing and unrestricted access to undocumented settings enabled the exploit. Wardle's proof-of-concept attacks demonstrated the ability to take pictures and write malicious files without user alerts. Meta patched the vulnerability hours after an Ars Technica report and stated the practical risk was minimal since it required local access to the user's device. The exploit comes amid scrutiny of Meta's AI agent, with Amazon having recently blocked Muse from its e-commerce platform. Despite this, Muse's launch has been successful—its first 12 days of estimated mobile app downloads reportedly outpaced ChatGPT's 12-day debut in the US and Canada, with Meta stock climbing 11 percent on Monday.
(Source:The Verge)