A researcher says a flaw in Meta's Muse Mac app lets any app or terminal command access users' Muse authentication tokens; Meta says it issued a hotfix
First reported by Ars Technica ·
Any app you run on your Mac can now potentially access your AI assistant's authentication tokens.
A zero-day vulnerability has been discovered in Meta's Muse AI assistant for macOS, allowing any local application or terminal command to access user authentication tokens. Security researcher Patrick Wardle identified the flaw, which enables attackers to redirect Muse's transcription endpoint to their own servers, thereby gaining complete control over the user's Muse account and connected services like WhatsApp and email. This capability allows malicious actors to leverage Muse's extensive privileges to perform actions such as sending sensitive data or making unauthorized purchases. Meta has acknowledged the vulnerability and stated it has issued a hotfix. The discovery comes as Amazon began blocking Muse from its platform, citing violations of its conditions of use for unauthorized AI agents making purchases on its site. Wardle plans to present further details on this and other AI assistant threats at an upcoming security conference.
The vulnerability in Meta's Muse AI assistant highlights a significant security oversight in how privileged AI agents handle authentication and access control. By allowing any local process to manipulate critical settings like transcription endpoints, Meta has created a pathway for attackers to easily hijack user accounts. This raises broader questions about the security architecture of deeply integrated AI assistants that require extensive system-level permissions, potentially undermining the security measures designed by operating system vendors like Apple.
The incident also underscores the growing tension between AI assistant functionality and platform security, as evidenced by Amazon's decision to block Muse. As AI assistants become more capable of acting on behalf of users across multiple services, platforms are increasingly scrutinizing their compliance with terms of service and security standards. This could lead to more restrictive policies for AI agents or a greater demand for standardized security protocols to ensure trust and safety for end-users.
AI-written summary. May contain errors.