Meta's AI assistant muse faces security concerns amid zero-day vulnerability and amazon block
Meta's AI assistant Muse has sparked security concerns after a zero-day vulnerability was discovered, allowing local apps and terminal commands full control over the agent. The issue raises questions about the platform's security claims, as Amazon recently blocked Muse from its site. Introduced a few weeks ago, Muse is designed to handle tasks like booking appointments, filling out forms, and customer service, while also making purchases, generating images, and connecting with various apps and services. The macOS app, which lacks a Windows version, integrates with WhatsApp, email, calendar, and social media accounts. Users must grant Muse access to their accounts and device resources, including file writing, microphone and camera access, and location tracking. Apple's security measures, aimed at preventing apps from accessing these resources, are reportedly undermined by Muse's design.
The assistant can create tools on the fly when needed, but this capability, combined with broad permissions, has drawn scrutiny. Critics argue that Muse bypasses Apple's security defenses, potentially exposing users to risks. The incident highlights growing concerns about AI assistants' security and privacy practices, especially as companies like Meta push for advanced functionalities without adequate safeguards.