Meta’s personal AI agent Muse has been found vulnerable to a local zero-day on Mac just two weeks after launch, according to the source report. Security researcher Patrick Wardle said an attacker only needs to run code under the current user account to change a hidden Muse setting and redirect voice requests to a server they control. The code does not require extra macOS permissions.
Once that setting is changed, the attacker could intercept what a user says to Muse, inject malicious instructions, and potentially obtain Muse authentication data. Because Muse can access system resources such as files and the camera, a malicious local program may be able to act through whatever permissions the user has already granted to Muse.
The issue is not described as a remote Mac compromise. An attacker must first get code running on the target machine. The report also noted that Meta had highlighted Muse’s security architecture at launch, including Muse Secure VM and a separate Sentinel Agent, but the first disclosed zero-day stems from a hidden setting in the Mac client that an ordinary local process can modify.
Meta’s personal AI agent Muse was found to contain a local zero-day flaw on Mac just two weeks after launch, according to BlockBeats. The issue was identified by security researcher Patrick Wardle.
Wardle said an attacker only needs to get a piece of code running under the current user account on a Mac to modify a hidden Muse setting and redirect voice requests to a server they control. The code does not need additional macOS permissions.
After that, the attacker could intercept what the user says to Muse, inject malicious instructions, and may also be able to obtain Muse authentication information.
Muse itself can access system resources including files and the camera. Any permissions the user has granted to Muse could then be invoked by malicious software through the agent.
The flaw is not described as a remote intrusion path into a Mac. An attacker must first get code to run locally on the device. BlockBeats said Meta had emphasized Muse’s security design at launch, including Muse Secure VM and a separate Sentinel Agent. But the first disclosed zero-day was tied to a hidden setting in the Mac client that can be changed by a standard local process.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.