Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

A simple ClickFix attack is only one way to completely hijack the new agent.

Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day

TL;DR

  • A zero-day vulnerability in Meta's AI assistant Muse allows any locally run app or terminal command to gain complete control of the agent.
  • The flaw enables attackers to change Muse's transcription endpoint to their own server, stealing authentication tokens and gaining full access.
  • macOS security expert Patrick Wardle discovered the vulnerability, demonstrating that a simple ClickFix attack can exploit it.
  • Amazon has begun blocking Muse from its site, stating it violates their Conditions of Use for unauthorized AI agents making purchases.
  • Wardle criticizes Meta's design decisions, suggesting a lack of security considerations in Muse's development.
  • The vulnerability arises from Muse's cloud-based dictation and its allowance for any app to control undocumented settings, including sensitive ones.