
Meta introduced Muse, a macOS AI assistant designed to handle tasks including booking appointments, filling forms, managing customer service interactions, making purchases, and generating content while integrating with user accounts across WhatsApp, email, calendars, and social media platforms. To function, the assistant requires extensive access to user authentication tokens and operating system resources including file writing, microphone, camera, location monitoring, and calendar access.
Security researcher Patrick Wardle discovered a zero-day vulnerability that allows any locally installed application or terminal command to access the authentication token controlling the Muse account, circumventing macOS security protections designed specifically to prevent such access. The flaw enables attackers to modify undocumented settings within the application, including the endpoint where voice transcription is processed. By redirecting this endpoint to an attacker-controlled server, threat actors can intercept user authentication tokens and gain complete control over the assistant’s functionality and access.
Wardle developed multiple proof-of-concept attacks demonstrating the vulnerability’s severity, including writing malicious files to disk and accessing device cameras in many cases without user notification. He attributed the vulnerability to specific design choices by Meta developers, including the decision to process dictation in cloud servers rather than using macOS’s built-in secure on-device transcription capabilities, and permitting any application to control sensitive configuration settings. Meta released a hotfix more than 12 hours after the vulnerability was publicly disclosed.
Separately, Amazon began blocking Muse from its platform, stating the assistant violated its conditions of use as an unauthorized AI agent. Amazon indicated that third-party applications making purchases on behalf of customers should operate transparently and respect service providers’ decisions regarding participation, comparing the requirements to those applied to food delivery and travel booking applications.
Security experts have raised concerns about the overall security approach taken during Muse’s development, questioning whether adequate consideration was given to threat modeling and security testing before the platform’s release.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI