Meta Muse AI Zero Day
So it turns out Meta's Muse AI has a pretty serious zero-day exploit. It seems Meta's long history of questionable security and privacy continues...
So it turns out Meta’s Muse AI has a pretty serious zero-day exploit. As reported by Dan Goodin in Ars Technica, it appears the macOS app has an easy way to gain access to a users Muse AI account:
The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, is anything but innocuous. It allows processes to change the endpoint where transcription occurs. Normally, it’s a server address operated by Meta. Attackers can exploit this flaw by changing the location to their own endpoint. Once that happens, the attackers have the token that gives complete control over the Muse account.
- Dan Goodin
Once an app has access to the account (by pointing the endpoint at the local app and stealing the token), it can ask Muse to perform tasks like writing malicious files to disk, record via the microphone, and even take photos. Yikes!
It seems Meta’s long history of questionable security and privacy continues…