AI & TechArtificial IntelligenceBigTech CompaniesCybersecurityNewswireWhat's Buzzing

Meta’s Muse AI Launches With Critical Security Flaw

▼ Summary

– Meta’s new AI assistant Muse was heavily hyped for privacy and security but faces scrutiny due to a critical zero-day vulnerability.
– The flaw allows locally run apps or terminal commands to gain complete control over the agent by stealing authentication tokens.
– Security expert Patrick Wardle demonstrated that attackers could exploit this to perform malicious actions like writing files or taking photos without detection.
– Amazon blocked access to Muse on its site, raising further questions about the assistant’s safety and reliability in production environments.
– Meta released a hotfix to patch the vulnerability shortly after the security risks were publicly disclosed and analyzed.

Meta’s new AI assistant, Muse, has faced immediate scrutiny following the discovery of a critical zero-day vulnerability. Despite CEO Mark Zuckerberg’s insistence that the tool is “built from the ground up for privacy and security,” the flaw allows locally run applications and terminal commands to seize complete control of the agent. The severity of the issue was underscored when Amazon began blocking access to Muse on its platform just days after the assistant’s launch.

Unprecedented System Access

Introduced a few weeks ago, Muse is designed to automate complex tasks such as booking appointments, filling out forms, and handling customer service interactions. It can also generate images, create documents, make purchases, and integrate with popular services like WhatsApp, email, and social media platforms. A notable feature is its ability to dynamically create tools for tasks that lack existing integrations. While the application is currently available exclusively for macOS, it requires users to grant extensive permissions to function properly. These permissions include authentication across multiple services and deep system-level access to resources such as disk writing capabilities, microphone and camera inputs, location tracking, and calendar data. This level of access effectively bypasses the protective barriers Apple has spent years implementing to shield users from malicious software and unauthorized command-line operations.

Exploiting Cloud-Based Dictation

The identified zero-day vulnerability specifically targets the token used to authenticate users within their Muse accounts. Because Meta developers allowed any locally installed app or executed code to modify undocumented settings, attackers could alter the endpoint where transcription occurs. Normally, this process directs data to Meta’s secure servers. However, by redirecting this endpoint to a malicious server, an attacker could intercept the authentication token, thereby gaining full administrative control over the user’s account.

Patrick Wardle, a prominent macOS security expert who uncovered the flaw, highlighted the ease with which the assistant’s privileges could be hijacked. “We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle explained. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” He demonstrated several proof-of-concept attacks that included writing malicious files to disk and capturing photos, often without triggering alerts even for vigilant users. Although Meta released a hotfix more than 12 hours after the initial report, the incident raises significant concerns about the architectural choices made during development.

Design Choices Under Fire

Wardle noted that specific design decisions facilitated the exploit, particularly the choice to perform dictation in the cloud rather than locally. By opting for cloud-based processing to facilitate logging, Meta ignored safer, device-local alternatives that have long been available on macOS. This decision exposed users to risks that could have been easily mitigated. The controversy emerges alongside broader industry discussions regarding AI safety, including recent reports of internal testing breaches involving models from Anthropic and Google. As calls to slow down AI development intensify, Meta’s handling of Muse’s security architecture faces intense scrutiny for prioritizing functionality over robust protection mechanisms.

(Source: Wired)

Topics

ai security vulnerabilities 95% privacy concerns 90% cybersecurity research 88% meta product launch 85% platform restrictions 75%
Show More