Zero-day in Meta’s Muse AI assistant lets local apps seize user authentication tokens
Security researcher Patrick Wardle disclosed a zero-day in Meta’s new Muse assistant for macOS that lets any local app or terminal command access the token that authenticates a user’s Muse account by changing an undocumented setting (including the transcription endpoint). The flaw can give attackers full control of the assistant and its privileges; Amazon has also begun blocking Muse from making purchases on its site and Meta did not respond to inquiries.