Back
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
SiTech AI Team2 წთ. საკითხავი

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

Ars Technica reports a 0-day in Meta's new assistant Muse: any locally run app or terminal command can take complete control of the account. Amazon has already blocked Muse.

Meta's new AI assistant Muse carries a 0-day that hands any locally run app or terminal command complete control of the agent, Ars Technica reported on September 21. The finding undercuts Mark Zuckerberg's claim that Muse is “built from the ground up for privacy and security.”

An assistant with unusual reach

Meta introduced Muse a few weeks ago. It books appointments, fills out forms, makes purchases and creates documents, the company says, and its macOS app links to a user's WhatsApp, email, calendar and social accounts. To work, it must be authenticated to each service and granted system permissions for files, the microphone, camera, location and calendars — access Apple normally walls off from installed apps and terminal commands.

The flaw

Meta let any locally executed code change a long list of undocumented settings, regardless of those permissions. Most are mundane, such as dark mode. One governs the endpoint where transcription happens, normally a server operated by Meta. Redirect it to an attacker's machine and the token authenticating the Muse account arrives there too.

Wardle's terminal command to Muse

“We can manipulate the agent and leverage its privileges to do whatever we want,” said Patrick Wardle, the macOS security expert who found the vulnerability. “Instead of writing a comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” His proof-of-concept attacks wrote malicious files and snapped pictures, often unnoticed. Meta did not answer emailed questions.

Muse's reply: such an attack is impossible

ClickFix is enough

Wardle traces the bug to two choices: Muse transcribes dictation in the cloud, where Meta can log it, rather than on-device as macOS allows, and any app may edit every undocumented setting. A simple variation of a ClickFix attack — which persuades users to run attacker-supplied commands themselves — was enough, he said. Wardle will detail the flaw at November's Objective by the Sea conference.

Amazon cuts Muse off

Roughly 12 hours earlier, Amazon blocked Muse from shopping on its site, calling it an “unauthorized AI agent [that] violates Amazon's Conditions of Use,” and asked Meta to remove Amazon from the assistant. The report follows two Meta posts defending the design of an assistant with unusual access to user data.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.