ELSEIF
Your brief EB
450 stories from 214 feeds 1266 clusters Refreshed 7 minutes ago next pull 18:11

TECH Signal 347 2 feeds carried it

Zero-day in Meta's Muse assistant allows local apps to hijack agent via token theft

A vulnerability in Meta's Muse AI assistant allows any locally installed app or terminal command to steal the authentication token, granting attackers complete control over the agent and its extensive system permissions.

WHY IT MATTERS

The flaw undermines the security model of an agent that requires broad access to user accounts, files, and hardware. It demonstrates that cloud-based transcription and undocumented settings can create critical attack surfaces that bypass standard operating system defenses.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Any local process can change undocumented settings to redirect Muse's transcription endpoint to an attacker-controlled server.

02

The exploit allows attackers to steal the authentication token, giving them full control over the agent's actions and data access.

03

Security expert Patrick Wardle identified the flaw, noting that using on-device dictation would have prevented the attack.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

Meta's Muse assistant, designed to handle tasks like booking appointments and making purchases, has been found to contain a critical zero-day vulnerability. The flaw allows any locally installed application or terminal command to gain unauthorized access to the authentication token that links the user to their Muse account. This means that even a simple, low-privilege process on the system can escalate its capabilities to match those of the highly privileged AI agent.

The technical root of the issue lies in two specific design choices: the use of cloud-based transcription for dictation and the ability for any local process to modify a long list of undocumented settings. By allowing processes to change the endpoint where transcription occurs, attackers can redirect sensitive user speech to their own servers. Once the transcription data is intercepted, the attacker obtains the token required to fully control the Muse agent, bypassing the need for traditional malware development.

This vulnerability is particularly concerning because Muse operates with extensive permissions, including access to WhatsApp, email, calendars, and the ability to write files to disk or access the microphone and camera. These permissions are intended to enable the agent to perform complex tasks, but they also create a massive attack surface. The fact that standard macOS security measures, which are designed to restrict app access to these resources, are effectively undone by Muse's architecture raises significant questions about the product's security posture.

Patrick Wardle, the security expert who discovered the flaw, highlighted that the use of cloud-based dictation was a critical mistake. macOS provides mechanisms for on-device transcription that would have kept the data secure and prevented the endpoint redirection attack. The decision to process dictation in the cloud, likely for logging or other backend purposes, introduced a vulnerability that could have been avoided with a safer, local alternative. This incident underscores the importance of considering security implications at the architectural level, especially for agents with such high privileges.

The discovery of this zero-day comes at a time when Meta is actively promoting the security and privacy features of its AI products. The vulnerability contradicts claims that Muse is 'built from the ground up for privacy and security,' and it highlights the risks associated with granting AI agents broad system access. For developers and users, this incident serves as a cautionary tale about the potential dangers of integrating powerful AI tools into systems without rigorous security testing and a clear understanding of the attack surface.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 2 feeds.

ORDERED BY FIRST SEEN
Ars Technica Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day Open ↗
Ars Technica via Hacker News Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day Open ↗