Urgent.News

What's breaking now, across thousands of outlets.

AI

Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw

Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.

Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw

Meta's new AI assistant, Muse, was released with a significant security flaw that could allow malicious actors to gain complete control over the user's account. Despite Meta CEO Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security," a zero-day vulnerability has been discovered that exposes serious privacy and security concerns.

The zero-day vulnerability allows any locally installed app or terminal command to gain access to the user's Muse account by manipulating a long list of undocumented settings. One particularly concerning setting enables processes to change the endpoint where transcription occurs, which, if exploited, could grant attackers access to sensitive user data and resources, including device cameras, microphones, and location tracking.

Meta released a hotfix to patch the zero-day vulnerability, but the design decisions made by the company's developers raised questions about the overall security and privacy of Muse. Two major design choices, specifically the use of cloud-based dictation and the ability for any app or command to control undocumented settings, were found to be problematic.

These decisions, according to security expert Patrick Wardle, suggest that Meta may have overlooked critical aspects of security and privacy during the development of Muse.

Amazon also responded to the issue by blocking users from using Muse to make purchases on its site, citing the app as an "unauthorized AI agent." This response highlights the severity of the security flaw and the potential risks it poses to users.

Written by urgent.news from Wired's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at wired.com →

More in AI

More from Wednesday 23 September →