NG Solution Team
Cybersecurity

Muse vulnerability could let attackers hijack a Mac in one click

Meta’s new AI assistant Muse is reportedly affected by a zero-day one-click vulnerability that could allow local attackers to take control of an entire Mac, security researcher Patrick Wardle said on X.

The exploit was unveiled as Amazon decided to block Muse from shopping on its platform. Meta currently does not have a Windows version of Muse for PC.

Muse vulnerability: how it works

According to Wardle, and as first reported by Ars Technica, the flaw lets “local malware/attackers invisibly hijack” a user’s Mac by abusing the macOS permissions Muse requires. Wardle explains that an attacker can change the endpoint where Muse sends dictation for transcription. The server address is normally pointed to one that belongs to Meta, but if altered the attacker can obtain the token that controls the Muse account.

From that point, Wardle said, the attacker does not need to deploy a specific trojan or additional code: they can simply take control of Muse and use it to access or steal data on the user’s machine.

Muse Secure VM and Meta’s position

Muse operates as a personal AI agent and requires extensive permissions on a user’s device to perform tasks and actions. Meta anticipated potential security concerns related to those permissions and said at launch that Muse was designed to run on “a dedicated secure computer with its own browser” called Muse Secure VM. “Personal agents need a new kind of secure computer, so Meta built one for everyone,” the company said. “Muse Secure VM has first-of-its-kind privacy, safety, and security protections engineered into it that no other agent provides.”

Wardle also noted design choices that contributed to the issue: Apple keeps dictation locally for its own applications and transcription features, whereas Meta opted to use the cloud for dictation, a decision Wardle said makes the exploit possible.

Related posts

How are travel disruptions in the Netherlands and security concerns in Greece affecting European travel?

James Smith

Did CodexField on BNB Chain execute a rug pull after its website and X (Twitter) account disappeared?

Jessica Williams

Is the US embassy in Bahrain warning Americans to shelter as sirens sound nationwide?

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy