TECHNOLOGY · VERIFIED DEVELOPMENT
Meta Patches Muse Exploit Allowing Attackers to Control AI Agent
WHY IT MATTERS
The patch is crucial in preventing potential attacks on Muse accounts, highlighting the importance of secure design decisions in AI-powered applications.
What happened
Meta has released a patch for its Muse macOS app after a zero-day vulnerability was discovered. The exploit, found by security researcher Patrick Wardle, allowed attackers with local access to a user's device to control the AI agent and gain access to Muse accounts.
The vulnerability was enabled by several design decisions, including cloud-based transcription processing and the ability of any app to control Muse's undocumented settings. According to Ars Technica, the bug utilized an undocumented Muse setting to redirect transcription processing to an attacker's endpoint, giving them access to the account.
The patch is intended to address this issue and prevent potential attacks.
DEVELOPING STORY
Story timeline
PRIMARY SOURCES
Meta patches Muse exploit that let attackers control the AI agent
The Verge · Jess Weatherbed · Discovery only; Vox Media copyright terms apply