Meta’s Muse reportedly has zero-day vulnerability that lets attackers take over your Mac
Met's popular AI assistant Muse has a concerning zero-day vulnerability, a new report claims.
Meta's AI assistant Muse, launched earlier this month, has reportedly been found to have a zero-day vulnerability that could allow attackers to take control of a user's Mac computer. Security expert Patrick Wardle noted the issue on X, stating that the vulnerability could enable local malware or attackers to stealthily hijack a user's Mac.
The vulnerability stems from the macOS permissions Muse requires, potentially allowing the attacker to access and modify the endpoint for transcription dictation, as well as the server address belonging to Meta. From there, the attacker can gain access to the token controlling the Muse account, without needing to deploy any specific trojan or code to steal data.
Muse is designed to run on a dedicated secure computer with its own browser called Muse Secure VM, but security measures built into it were reportedly insufficient to prevent the vulnerability. The zero-day vulnerability is not yet addressed by Meta, but they are likely to respond soon.
Written by urgent.news from Mashable's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Amazon is keeping Meta’s Muse out of its shopping carts businessinsider.com
- Meta Muse AI app flaw lets local malware redirect dictation traffic theregister.com
- Meta’s new Muse AI app tops charts, draws strong reviews businesstimes.com.sg
- No Shirt, No Shoes, No Service: Amazon Blocks Meta’s Muse AI From Shopping cnet.com
- CNBC Daily Open: AI trade goes Meta after Muse launch cnbc.com