Meta AI Assistant 'Muse' Fully Compromisable via 0-Day Vulnerability
Key point
macOS security expert Patrick Wardle discovered and disclosed a 0-day vulnerability in Meta's AI assistant Muse that allows full account control through authentication token theft.
Details
macOS security expert Patrick Wardle discovered and disclosed a critical 0-day vulnerability in Meta's AI assistant Muse. Muse is a macOS app that performs various tasks such as reservations, purchases, and image generation, with broad access permissions to user accounts and system privileges.
Vulnerability Mechanism and Attack Vector
The discovered vulnerability allows locally installed apps or terminal commands to access Muse's authentication token regardless of macOS permission controls. In particular, if the voice recognition (transcription) endpoint is changed to an attacker's server, the user's voice prompts pass through the malicious server where malicious commands are inserted, enabling full control of the Muse account.
According to Wardle's proof of concept (PoC), exploiting this vulnerability allows actions such as writing malicious files to disk or taking photos via the camera without warning the user. It was confirmed that even a simple ClickFix variant could lead to device infection and account takeover.
Security Design Criticism and Response
Wardle criticized Muse's adoption of cloud-based voice processing to keep logs and its design allowing all apps to control undocumented sensitive settings as security flaws. He argued that adopting macOS's on-device processing approach could have blocked such attacks.
Meanwhile, approximately 12 hours before Wardle's vulnerability disclosure, Amazon blocked Muse's shopping feature, considering it an 'unauthorized AI agent'. Meta did not immediately respond to the question, and Wardle emphasized that much stricter security standards are needed considering the high privileges of AI assistants.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.