
A simple ClickFix attack is only one way to completely hijack the new agent. Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day. Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is โbuilt from the ground up for privacy and security.โ A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts.
Further raising questions, Amazon on Sunday began blocking Muse from its site. The assistant โbooks appointments, fills out forms and handles customer service,โ โproactively takes tasks off your plate,โ and can โmake purchases, generate images, create documents, and connect with your favorite apps and services.โ The macOS app (curiously, thereโs no Windows version) also works with a userโs WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesnโt exist, Muse creates one on the fly.
Meta doth hype Muse security too much Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat.
Muse completely undoes these default measures.
Discover more from ChuckysCarnage
Subscribe to get the latest posts sent to your email.
