AI & TechArtificial IntelligenceBigTech CompaniesCybersecurityNewswire

Meta Fixes Muse Exploit That Let Attackers Control AI Agent

▼ Summary

– Meta released a patch for its Muse macOS app after security researcher Patrick Wardle discovered a zero-day vulnerability.
– The flaw allowed attackers with local access to redirect transcription processing and take control of the AI agent’s privileges.
– Wardle demonstrated that the exploit could be used to manipulate the agent, take pictures, and write malicious files without user alerts.
– Meta responded by issuing a hotfix and downplaying the risk as a local privilege escalation rather than a remote exploit.
– Despite the security issue, Muse has seen high download rates surpassing ChatGPT’s debut, though Amazon recently blocked its e-commerce access.

Meta has released an urgent update for its Muse macOS application to resolve a critical zero-day vulnerability that allowed attackers to hijack the AI agent. The flaw, identified by security expert Patrick Wardle, exploited an undocumented configuration option within the app. This setting permitted malicious actors executing code locally to reroute transcription tasks from Meta’s secure servers to endpoints they controlled. By intercepting this data flow, an attacker could gain unauthorized access to the user’s Muse account, effectively bypassing standard security protocols.

The vulnerability stemmed from several architectural choices, most notably the decision to process dictation in the cloud rather than on the device itself. Additionally, the software allowed any installed application to modify all of Muse’s hidden settings without restriction. Wardle demonstrated the severity of these design flaws through proof-of-concept attacks that enabled him to capture screenshots and write malicious files to the disk. In many instances, these actions occurred without alerting the user, highlighting significant gaps in transparency and control.

Wardle emphasized the potential dangers of such privileges. “We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself,” he told Ars Technica. He further criticized the development approach, stating, “At the very least, they should be thinking about security from the very start, and they are just not.”

This revelation contrasts sharply with Meta’s earlier marketing, which heavily promoted Muse’s privacy and security features upon its launch. Meta moved quickly to patch the issue within hours of the report becoming public. Company officials argued that the immediate threat to users was limited because the exploit required prior local access to the victim’s machine. David Singleton of Meta Superintelligence Labs clarified the nature of the risk on X: “This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,” Singleton said. “Nonetheless, we have issued a hotfix to the app to address the issue.”

Despite the rapid resolution, the incident occurs during a period of intense scrutiny for Meta’s AI initiatives. Amazon recently blocked Muse from accessing its e-commerce platform, alleging that Meta failed to obtain necessary permissions. Nevertheless, the product’s market reception remains strong. During its first twelve days, estimated downloads of the Muse mobile app reportedly surpassed those of ChatGPT’s debut in the US and Canada. Following the news of the fix and continued adoption, Meta’s stock price rose by 11 percent on Monday, signaling investor confidence despite the technical setback.

(Source: The Verge)

Topics

zero-day vulnerability 95% ai security risks 90% product patch response 85% market competition 80% local privilege escalation 75%
Show More