The Actual News

Fact-first summaries of the news — stay informed, stay grounded.

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Summary

Meta released an AI assistant called Muse that helps with tasks like booking appointments and managing social media. A security expert found a serious weakness that lets other apps on a Mac control Muse fully, risking users’ private data. Amazon has started blocking Muse due to these issues.

Key Facts

  • Muse is an AI assistant by Meta that works on macOS to perform tasks like making purchases and managing calendars.
  • It requires broad access to users' accounts and device features like microphone, camera, and files.
  • A zero-day vulnerability allows any local app or terminal command on macOS to get control over Muse’s authentication token.
  • Attackers can change settings to redirect data to their own servers and take full control of a Muse account.
  • Security expert Patrick Wardle demonstrated attacks using this flaw that can take pictures or write malicious files without user alerts.
  • Meta promoted Muse as secure and private but has not responded to questions about the security hole.
  • Amazon began blocking Muse from its site after the flaw was revealed.
  • The flaw exists partly because Muse processes dictation data in the cloud instead of securely on the device, increasing risk.
Read the Full Article

This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.

Save articles & personalize your feed — Create a free account