Meta’s Muse reportedly has zero-day vulnerability that lets attackers take over your Mac
Meta launched its new AI assistant Muse to much fanfare earlier this month.
Now, just a few weeks later, a zero-day vulnerability has reportedly been discovered that could put access to your entire Mac computer in the wrong hands. (Meta currently does not have a Windows version of Muse for PC.) macOS security expert Patrick Wardle posted on X about the vulnerability with the Muse app.
According to Wardle, and as first covered by Ars Technica , the vulnerability lets "local malware/attackers invisibly hijack" a user's Mac.
This Tweet is currently unavailable.
It might be loading or has been removed.
Wadle explains that thanks to the macOS permissions that Muse requires, an attacker could access and change the endpoint where transcription for dictation occurs.
The server address is pointed to one that belongs to Meta, but with this change, the attacker could then gain access to the token that controls the Muse account.
From there, the attacker doesn't need to deploy any specific trojan or code to steal data from a user's machine, Wardle explained.
They can simply take control of Muse to do so.
As a personal AI agent, Muse is able to help complete tasks and perform actions on a user's computer.
This requires that a user give Muse a lot of permissions on their device, more than a user would provide to most other third-party applications.
Other popular AI agents like OpenClaw have the same security risks .
Meta predicted the potential security issues with Muse requiring so many system permissions.
The company addressed the issue at launch, saying Muse was designed to run on "a dedicated secure computer with its own browser" called Muse Secure VM.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on mashable.com — the content belongs to Mashable.