Meta's Muse AI assistant faces major security vulnerability
Meta's new AI assistant, Muse, has been found to have a critical zero-day vulnerability that allows attackers to take full control of user accounts. Security expert Patrick Wardle discovered the flaw, which enables any locally installed app or terminal command to access the token used for user authentication. This allows attackers to redirect transcription services to their own endpoints, granting them complete control over Muse accounts. Wardle demonstrated how attackers could exploit this flaw to perform actions like writing malicious files and capturing photos without user awareness.
Meta released a hotfix 12 hours after the vulnerability was disclosed, but Wardle criticized the company for not addressing the security risks adequately. He pointed out that Muse's design choices, such as cloud-based transcription and allowing any app to control undocumented settings, made the exploit possible. Amazon also began blocking Muse from its site, citing violations of its terms of service. Wardle plans to discuss the vulnerability further at the Objective by the Sea security conference in November.