
Meta introduced Muse, a new AI assistant designed to handle tasks including scheduling appointments, completing forms, making purchases, and generating content. The macOS application integrates with users’ WhatsApp, email, calendar, and social media accounts, requiring authentication and broad operating system permissions to function.
A zero-day vulnerability discovered by macOS security researcher Patrick Wardle allows any locally installed application or terminal command to gain access to the authentication token controlling the Muse account, regardless of the permissions the app itself possesses. The flaw exists in how Muse handles undocumented settings that can be modified by any process on the system. While most settings control benign features like dark mode, one setting allows changing the endpoint where voice transcription occurs. Attackers can redirect this to their own server, intercepting the authentication token and gaining full control of the account and its associated services.
Wardle developed proof-of-concept attacks demonstrating the vulnerability’s severity, including writing malicious files to disk and activating the camera with no user notification. He attributed the vulnerability to design choices made during development, particularly the decision to process dictation in the cloud rather than using macOS’s built-in on-device transcription capabilities. He also criticized the broad permissions allowing any application to control settings meant for managing the user interface.
Meta released a hotfix more than 12 hours after the vulnerability was disclosed publicly. The company had previously published security documentation emphasizing Muse’s privacy and safety design. Separately, Amazon began blocking Muse from its platform, stating that third-party agents making purchases on behalf of customers must operate transparently and respect retailer decisions about participation.
Wardle expressed concern about the security approach, noting that developers demonstrated insufficient attention to security considerations from the initial design phase, raising broader questions about the security standards applied to AI assistant development.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI