Meta patches Muse vulnerability that led to AI agent control
A zero-day vulnerability discovered by security researcher Patrick Wardle allowed attackers to take over the AI agent and redirect transcription processes.
Meta has released a patch to address a security vulnerability in its Muse app developed for macOS. The flaw allowed individuals running local code to control the AI agent and gain account access.
Discovery of the Zero-Day Vulnerability
Security researcher Patrick Wardle discovered a critical security vulnerability in Meta's Muse macOS application. This flaw made it possible for attackers to redirect transcription processes to their own endpoints.
App Design Decisions
According to the findings, cloud-based dictation processes and the fact that the app's undocumented settings could be controlled by any software paved the way for this security vulnerability.
Attack Scenarios and Meta's Response
Developed proof-of-concept attacks demonstrated that photos could be taken without alerting users and malicious files could be written to disk. Meta, following the report, quickly patched the flaw.
Platform Restrictions and Downloads
Following these developments, Amazon blocked the Muse app's access to its e-commerce platform. Despite this, the mobile version of the app initially achieved strong download figures.