
Meta’s newly launched Muse AI assistant, introduced a few weeks ago, has been found to contain a critical zero-day vulnerability that undermines the company’s security assurances. The macOS application, which handles tasks including appointment booking, form completion, customer service interactions, and account purchases, was designed to work with users’ WhatsApp, email, calendar, and social media accounts. To function, Muse requires extensive permissions to access device resources and user authentication tokens.
Security researcher Patrick Wardle discovered that any locally installed application or terminal command can exploit the flaw to access the authentication token that grants complete control over a Muse account. The vulnerability stems from design choices that allow any process to modify undocumented settings, including one that controls where voice transcription is processed. By redirecting this transcription endpoint to a malicious server, attackers can intercept user voice prompts and authentication tokens, potentially manipulating the assistant to execute unauthorized actions. Wardle demonstrated proof-of-concept attacks including writing malicious files to disk and activating the device camera without user awareness.
Wardle attributed the vulnerability to insufficient security consideration during development. He noted that Meta chose to process dictation in the cloud rather than using macOS’s built-in secure on-device transcription capabilities. Additionally, the decision to allow any application to control all undocumented settings created an unnecessary attack surface. Meta released a hotfix more than 12 hours after the vulnerability was publicly disclosed.
Separately, Amazon began blocking Muse from its platform earlier this week, citing the application as an unauthorized agent that violates its terms of service. Amazon stated that third-party applications making purchases on behalf of customers should operate transparently and respect business decisions about participation, comparing Muse to food delivery and travel booking applications that work directly with service providers.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI