Meta's Muse: Security at Stake
Mark Zuckerberg, founder and CEO of Meta, has promoted the company's new AI assistant, Muse, as an example of security and privacy. However, a zero-day vulnerability that allows local applications and terminal commands to take full control of the agent is raising serious doubts about this narrative. To complicate matters further, Amazon has started blocking Muse on its website, increasing concerns about the assistant's security.
Muse was recently introduced and is an assistant capable of scheduling appointments, creating documents, and even shopping. It integrates with the user's WhatsApp, email, calendar, and social networks, but is only available for macOS. The detail is that, to function, Muse requires access to various system permissions, such as microphone, camera, location, and calendar. These permissions are precisely what Apple tries to protect with its defenses, but Muse seems to ignore these barriers.
The Vulnerability that Exposes Muse
The security flaw allows any application or terminal command to access the token that authenticates users to Muse. This means that any code executed locally can alter undocumented settings. While some of these settings are harmless, others are critical. One of them allows changing the endpoint where the transcription occurs, which is usually a Meta server. By altering this endpoint, attackers can redirect traffic to their own servers, gaining full control over the Muse account.
Patrick Wardle, a macOS security expert, discovered this vulnerability. He demonstrated that it is possible to manipulate the assistant to perform malicious actions, such as writing malicious files to disk and taking photos without the user noticing. Wardle noted that Meta's choice to perform transcription in the cloud, where it can be logged, contributed to the exploitation of the vulnerability. If the transcription were done locally, the attack would not be possible.
Amazon Blocks Muse and Meta Under Pressure
Even before Wardle disclosed the flaw, Amazon had already begun blocking the use of Muse for shopping on its site, claiming that the assistant violated its terms of use. The company stated that third-party applications that shop on behalf of customers must operate transparently and respect the decisions of service providers.
Meta has published two posts in recent weeks about Muse's design decisions. However, in light of the revelations, it is clear that these measures were not sufficient to ensure the assistant's security. Trust in Muse is shaken, and Meta needs to act quickly to fix the problem.
The Challenge of Protecting AI Assistants
The case of Muse raises important questions about security in AI assistants. As Wardle points out, the security of these applications needs to be a priority from the start. It's not about achieving perfection, but ensuring that vulnerabilities are not so easy to exploit.
The vulnerability of Muse is a reminder that, despite promises of security, reality can be quite different. And while Meta works to resolve the issue, users should remain vigilant and question how much they can truly trust AI assistants that require such broad access to their data and devices.
In the end, security in technology is a cat-and-mouse game. And, in this case, the mouse seems to have gotten ahead. Meta will have to catch up to regain users' trust.





Comments (0)
Comments are moderated and if they violate our Terms and Conditions of use, the comment will be deleted. Persistence in violation will result in a ban of your account.