Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Summary
Meta released an AI assistant called Muse that helps with tasks like booking appointments and managing social media. A security expert found a serious weakness that lets other apps on a Mac control Muse fully, risking users’ private data. Amazon has started blocking Muse due to these issues.Key Facts
- Muse is an AI assistant by Meta that works on macOS to perform tasks like making purchases and managing calendars.
- It requires broad access to users' accounts and device features like microphone, camera, and files.
- A zero-day vulnerability allows any local app or terminal command on macOS to get control over Muse’s authentication token.
- Attackers can change settings to redirect data to their own servers and take full control of a Muse account.
- Security expert Patrick Wardle demonstrated attacks using this flaw that can take pictures or write malicious files without user alerts.
- Meta promoted Muse as secure and private but has not responded to questions about the security hole.
- Amazon began blocking Muse from its site after the flaw was revealed.
- The flaw exists partly because Muse processes dictation data in the cloud instead of securely on the device, increasing risk.
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.