NEWS · COMPANIES · #771
Zero-day in Meta’s Muse AI assistant lets local apps seize user authentication tokens
Security researcher Patrick Wardle disclosed a zero-day in Meta’s new Muse assistant for macOS that lets any local app or terminal command access the token that authenticates a user’s Muse account by changing an undocumented setting (including the transcription endpoint). The flaw can give attackers full control of the assistant and its privileges; Amazon has also begun blocking Muse from making purchases on its site and Meta did not respond to inquiries.
KEY POINTS
- Security researcher Patrick Wardle disclosed a zero-day in Meta’s new Muse assistant for macOS that lets any local app or terminal command access the token that authenticates a user’s Muse account by changing an undocumented setting (including the transcription endpoint).
- The flaw can give attackers full control of the assistant and its privileges; Amazon has also begun blocking Muse from making purchases on its site and Meta did not respond to inquiries.
- This matters because Muse has unusually broad access to user accounts and device resources, so a local exploit that steals its token can let attackers perform actions (files, photos, purchases, messages) with the assistant’s privileges and exfiltrate sensitive data.
WHY IT MATTERS
This matters because Muse has unusually broad access to user accounts and device resources, so a local exploit that steals its token can let attackers perform actions (files, photos, purchases, messages) with the assistant’s privileges and exfiltrate sensitive data.
SOURCES & TIMELINE
2Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. Meta introduced Muse a few wee…
‘They should be thinking about security from the very start, and they are just not.’ Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processi…