Urgent.News

What's breaking now, across thousands of outlets.

Tech

Meta Muse AI app flaw lets local malware redirect dictation traffic

Ad biz promises users control while bug could expose voice prompts

Meta Muse AI app flaw lets local malware redirect dictation traffic

Meta's Muse AI assistant app, touted for its security, may contain a vulnerability that allows local malware to redirect dictation traffic and potentially access sensitive information. The app utilizes a feature called Muse Secure VM, which grants users control over its access levels. However, security researcher Patrick Wardle discovered what he calls a "local zero-day" that could enable an unprivileged local process to modify Muse's settings and redirect dictation traffic to an attacker-controlled endpoint.

This flaw, if exploited, could lead to prompt injection, theft of authentication material, and abuse of user-granted access. Wardle likens the situation to living in an apartment building, where a malicious neighbor could gain access to all apartments. While Apple has implemented strong security measures like its Transparency, Consent, and Control (TCC) framework, Wardle worries that AI apps, due to their extensive access requirements, could become a single point of failure and undermine operating system security controls.

He also questions whether AI companies are prioritizing their own app security. Wardle suggests that Apple's on-device local dictation service could mitigate the risk, but Meta opted not to use it, potentially increasing the attack surface due to their desire for user data. As AI companies race to develop new technologies, Wardle believes privacy and security are not top priorities. Meta declined to comment on the vulnerability.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

QueerCade (Parts 1 & 2)

This is a submission for the Sanity Challenge, Path One: Ship an Agent That Queries Real Content This is a submission for the Sanity Challenge, Path Two: Vibe-Code Something Strange What I Built I…

Get your free VLESS proxy with one command: Xray + XHTTP on Alwaysdata

Мне был нужен свой прокси за границей, но платить за VPS ради него не хотелось. Бесплатные варианты быстро кончились. Oracle Cloud просит иностранную карту. Render у меня открывается только через VPN.

More from Monday 21 September →