Meta Patches Muse AI Backdoor Vulnerability
Meta patched a zero-day vulnerability in its Muse macOS app, allowing attackers to control the AI agent.
"Meta's AI had a secret backdoor, but they slammed it shut fast. Still, it's a reminder: even the biggest tech can have hidden flaws. Stay sharp out there!"
Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability. Security researcher Patrick Wardle found a bug utilizing an undocumented Muse setting that could allow attackers running local code to redirect transcription processing from Meta’s servers to their own endpoint, granting access to the Muse account. This flaw was reportedly enabled by design decisions, including cloud-based dictation and allowing any app to control Muse's undocumented settings.
Wardle's proof-of-concept attacks demonstrated the ability to take pictures and write malicious files to disk via Muse without user alerts. He stated that attackers could manipulate the agent and leverage its privileges. Meta patched the vulnerability quickly, asserting that real-world security concerns were minimal as the exploit required local access to the user’s device, making it a local privilege escalation attack rather than a remote one.
David Singleton of Meta Superintelligence Labs confirmed a hotfix was issued to address the issue. This vulnerability comes as Meta's AI agent faces scrutiny, despite its mobile app reportedly outpacing ChatGPT's initial downloads in the US and Canada during its first 12 days, contributing to an 11 percent climb in Meta stock on Monday.
This incident highlights the critical importance of robust security measures in AI development, especially for applications with privileged access. Businesses deploying AI solutions must prioritize security from the outset to prevent potential misuse and maintain user trust, which can impact market perception and stock performance.
Find the right AI tool for your business
Chat with Insta and get matched to the right tool in seconds.
Try Insta Tool Finder →