Meta fixes Muse vulnerability that allowed control of AI agent — The Verge
Meta released an update for the Muse app on macOS after discovering a zero-day vulnerability that could have allowed an attacker to take control of the AI agent. As The Verge reports, exploiting the flaw required local access to the user's device, but it could have opened access to the Muse account.
How the vulnerability worked
Cybersecurity researcher Patrick Wardle found that the issue was linked to an undocumented Muse setting. It allowed a program already running code locally on the computer to redirect transcription processing from Meta's servers to an endpoint controlled by an attacker. This could have given a potential attacker access to the Muse account.
According to the publication, several features of the app's design contributed to the vulnerability: dictation in Muse was processed in the cloud, and any program could control all of Muse's undocumented settings.
More current news is available on the UA.News Telegram channel Telegram.
Attack demonstration and Meta's response
During testing, Wardle created demonstration attacks that made it possible to take photos through Muse and write malicious files to disk. In many cases, the app did not warn the user about such actions.
Wardle told Ars Technica that an attacker could manipulate the agent and use its privileges to perform various actions without creating separate sophisticated malware for macOS. Meta fixed the issue within hours after the publication of the Ars Technica article. The company said it involved local privilege escalation rather than a remote attack, so Meta assessed the practical security risks as minimal.