Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day



Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.

Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly.

Meta doth hype Muse security too much

Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures.

The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, is anything but innocuous. It allows processes to change the endpoint where transcription occurs. Normally, it’s a server address operated by Meta. Attackers can exploit this flaw by changing the location to their own endpoint. Once that happens, the attackers have the token that gives complete control over the Muse account.



Source link

  • Related Posts

    Why Is Your Laptop Fan So Loud?

    Here’s how to know whether it’s cause for concern. DC Studio/Shutterstock Whether you’re a hardcore gamer or a hardworking student, you probably know that the best laptops for…

    Continue reading
    Napster Developing AI Teacher Clones to Provide Personalized Homework Support

    Napster is entering the education field. The former music-streaming giant, now an AI company, plans to use AI to produce what it calls “digital twins” of teachers who can answer…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Save Up to 20% Off Tournament-Grade PS5, Xbox, and PC Controllers During SCUF’s It’s Time to Win Sale

    Save Up to 20% Off Tournament-Grade PS5, Xbox, and PC Controllers During SCUF’s It’s Time to Win Sale

    Why Is Your Laptop Fan So Loud?

    Why Is Your Laptop Fan So Loud?

    My Empire of Dirt (Spoken Word Video)

    Paramount Skydance reaches settlement with states over Warner Bros. merger

    Paramount Skydance reaches settlement with states over Warner Bros. merger

    Lovebirds Spring 2027 Ready-to-Wear Runway, Fashion Show & Collection Review

    Lovebirds Spring 2027 Ready-to-Wear Runway, Fashion Show & Collection Review

    Joint statement by Prime Minister Carney and Prime Minister of Norway Jonas Gahr Støre

    Joint statement by Prime Minister Carney and Prime Minister of Norway Jonas Gahr Støre