Meta Muse AI app flaw lets local malware redirect dictation traffic
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM.
"Each person stays in control of their Muse and decides how much access it gets," the ad biz declared, echoing prior expansive claims about the privacy of its data gathering business.
But Meta's musing about Muse appears to be a bit overstated: an attacker capable of executing local code may be able to gain more access than a Muse user might expect.
Security researcher Patrick Wardle, founder of nonprofit Objective-See, has devised a proof-of-concept called not-a-mused for what he describes as a local zero-day in the Muse macOS app that allows an unprivileged local process to redirect Muse's dictation traffic and potentially abuse access granted to the app.
Muse, he explains in the project repo, has an undocumented setting called endo_voyager_dictation_endpoint that an attacker running code locally can modify without special privileges to redirect dictation traffic to an attacker-controlled endpoint, potentially exposing dictated audio and prompts sent to the backend AI model.
The flaw could enable prompt injection, the theft of authentication material, and abuse of whatever access the user has granted to Muse.
The vulnerability is not an issue for a remote attacker.
It requires the ability to run local code.
So the main concern, says Wardle, is that the vulnerability gives local malware far broader access than it would have otherwise.
Essentially, it's a privilege escalation vulnerability.
In a phone interview with The Register, Wardle likened the situation to living in an apartment building.
"Just because a bad neighbor moves in doesn't mean that that neighbor automatically has access to all the apartments," he said.
Apple, said Wardle, has done a really good job with its Transparency, Consent, and Control (TCC) framework, which manages access to sensitive data on macOS, and with privilege separation.
But his concern is that AI apps undo these barriers because they request or require so much access to data and tools.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.