Meta Patches Critical Zero-Day in Muse AI Assistant
Meta patched a zero-day vulnerability in its Muse macOS app that allowed attackers to control the AI agent.
"Meta's Muse AI had a serious flaw, letting attackers run wild. Even with a quick fix, it's a stark reminder: AI needs serious security from day one."
Meta has issued a patch for its Muse macOS app after a zero-day vulnerability was discovered. Security researcher Patrick Wardle found the bug, which utilized an undocumented Muse setting, enabling potential attackers to redirect transcription processing from Meta's servers to their own endpoint. This allowed attackers to gain access to the Muse account and manipulate the AI agent.
The vulnerability reportedly stemmed from several design decisions, including cloud-based dictation and allowing any app to control Muse's undocumented settings. Proof-of-concept attacks demonstrated by Wardle showed the ability to take pictures and write malicious files without user alerts. While Meta quickly addressed the issue, stating the exploit required local access and posed a low practical risk, the incident highlights security concerns with AI helpers.
This exploit comes as Meta's AI agent faces scrutiny, despite a successful launch where Muse mobile app downloads reportedly outpaced ChatGPT's initial debut in the US and Canada. The company's stock climbed by 11 percent on Monday following the launch. However, the incident underscores the inherent dangers and security considerations for AI assistants.
This incident highlights the critical importance of robust security measures in AI applications, especially those with privileged access. Businesses deploying or relying on AI agents must prioritize security from the outset to prevent potential data breaches and system compromises. Even local vulnerabilities can be exploited if malicious code is already present.
Find the right AI tool for your business
Chat with Insta and get matched to the right tool in seconds.
Try Insta Tool Finder →