Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Key Points:
- Meta CEO Mark Zuckerberg touted Muse, the company's new AI assistant, as highly secure and privacy-focused, but a zero-day vulnerability discovered by security expert Patrick Wardle allows any local app or terminal command on macOS to gain full control over Muse accounts.
- The flaw lets attackers redirect Muse’s transcription endpoint to a malicious server, capturing authentication tokens and enabling unauthorized actions like accessing WhatsApp messages, taking pictures, and writing files without user alerts.
- Muse requires broad permissions on macOS and access to multiple user accounts and services, undoing many built-in Apple security protections, which raises serious concerns about Meta’s design decisions and overall security testing.
- Amazon has blocked Muse from its site, citing violations of its Conditions of Use, and requested Meta remove Amazon integration from the assistant, highlighting broader industry resistance to third-party AI agents making purchases on behalf of users.
- Wardle plans to present detailed findings on this vulnerability and other AI assistant threats at an upcoming security conference, emphasizing that despite Meta’s claims, Muse cannot currently be trusted to safeguard user privacy and security.