Back
Meta's Muse AI Assistant Rolled Out With a Serious Security Flaw
SiTech AI Team3 წთ. საკითხავი

Meta's Muse AI Assistant Rolled Out With a Serious Security Flaw

A zero-day in Meta's Muse assistant let any locally run app or terminal command take full control of the agent, undoing macOS protections Apple spent years building. Meta shipped a hotfix more than 12 hours after the report.

Meta began rolling out Muse, its new AI assistant, a few weeks ago: a macOS app that "books appointments, fills out forms, and handles customer service," makes purchases and connects to a user's WhatsApp, email and calendar accounts. Founder Mark Zuckerberg said Muse was "built from the ground up for privacy and security." A zero-day vulnerability found in the app puts that claim in doubt.

What the flaw allowed

The bug was discovered by Patrick Wardle, a macOS security expert, and published by Ars Technica. Meta designed Muse so that any installed app or executed code — whatever permissions macOS gives it — can change a long list of undocumented settings, bypassing protections Apple has spent years building into macOS. Most are harmless, such as dark mode. One was not: it let a process redirect the endpoint where transcription happens. That endpoint is normally a server run by Meta; an attacker could point it at a machine of their own and with it receive the token that authenticates the user's Muse account.

A single ClickFix is enough

Wardle built working proof-of-concept attacks that wrote malicious files to disk and snapped pictures, often with no indication even to an attentive user. All that is required is a variation of ClickFix, a trick that gets people to run malicious code themselves. An attacker's server sits between the user and Meta's endpoint as a proxy; when the user speaks a voice prompt, it adds a prompt invoking a malicious command, such as sending an archive of all WhatsApp messages to the attacker. The account token then reaches the malicious server automatically, giving permanent control.

He attributed the root cause to design choices such as cloud-based dictation instead of on-device transcription. "We can manipulate the agent and leverage its privileges to do whatever we want," he told Ars. "So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself."

Muse's response to Wardle's smuggled prompt

Meta's response and Amazon's block

Meta released a hotfix more than 12 hours after the report went live. David Singleton of Meta Superintelligence Labs said on X that the flaw was "not a remote exploit" and the practical risk "quite low," since harming a user requires malicious code already running on their machine. Wardle said the designers "didn't, in my opinion, think about security, which is really worrisome." About 12 hours before the disclosure, Amazon began blocking shopping with Muse, calling it an "unauthorized AI agent [that] violates Amazon's Conditions of Use." Wardle plans to detail the vulnerability at the Objective by the Sea conference in November.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.