Meta’s Muse has a serious 0-day
First reported by Ars Technica ·
Meta's AI assistant is now protected against account hijacking via its zero-day vulnerability.
Meta's AI assistant, Muse, has a zero-day vulnerability allowing local applications and terminal commands to gain complete control of the agent. Security expert Patrick Wardle discovered that any app or terminal command can alter undocumented settings, including the transcription endpoint. Attackers can redirect this to their own server, intercepting the authentication token and gaining full access to the Muse account. Muse, which integrates with user accounts like WhatsApp and email, requires extensive macOS permissions for its functionality, including accessing microphones, cameras, and calendars. Wardle demonstrated proof-of-concept attacks that could steal data or perform unauthorized actions without user awareness. Meta released a hotfix for the vulnerability approximately 12 hours after its disclosure. Concurrently, Amazon began blocking Muse from its site due to violations of its conditions of use regarding unauthorized AI agents making purchases.
The discovery of a critical zero-day in Meta's Muse AI assistant highlights the significant security risks inherent in deeply integrated AI agents. Muse's ability to control user accounts and device resources, while intended for convenience, created a pathway for exploitation. The vulnerability underscores a broader challenge for AI developers: balancing powerful functionality with robust security measures, especially when dealing with sensitive user data and operating system-level permissions.
Amazon's blocking of Muse indicates a growing trend of platform providers scrutinizing and enforcing their terms of service against third-party AI agents. This move suggests that AI assistants acting on behalf of users will face increasing oversight regarding their operational transparency and adherence to platform rules. Companies like Meta will need to proactively address these concerns and potentially adopt more standardized protocols for AI agent interactions to ensure wider platform compatibility and user trust.
AI-written summary. May contain errors.