Skip to content
Ars Technica·

🔒Meta's Muse AI Assistant Exposed Zero-Day Vulnerability

Muse's zero-day flaw lets attackers take over accounts

TL;DR

Meta's Muse AI assistant, designed to automate tasks, has a zero-day vulnerability that lets attackers take full control of user accounts. The flaw was discovered by Patrick Wardle and involves changing the endpoint for transcription to steal user tokens.

Meta's Muse AI assistant, designed to automate tasks like booking appointments and filling out forms, has a zero-day vulnerability that lets attackers take full control of user accounts. The flaw, discovered by macOS security expert Patrick Wardle, allows attackers to change the endpoint where transcription occurs, giving them access to the token that authenticates users to their Muse account. This means once an attacker gains control, they can permanently take over the account. Muse's ability to access a broad range of operating system-restricted device resources undoes Apple's default security measures, making the vulnerability particularly dangerous. Amazon blocked Muse from its site roughly 12 hours before Wardle disclosed the flaw, citing it as an unauthorized AI agent violating Amazon's Conditions of Use. The vulnerability will be discussed in detail at the Objective by the Sea security conference in November.

Meta's Muse AI Assistant Exposed Zero-Day Vulnerability — Ars Technica

Key Points

1

Meta's Muse AI assistant has a zero-day vulnerability that lets attackers take full control of user accounts, discovered by Patrick Wardle.

2

The vulnerability involves changing the endpoint for transcription to steal user tokens, giving attackers permanent control over the account.

3

Amazon blocked Muse from its site roughly 12 hours before Wardle disclosed the flaw, citing it as an unauthorized AI agent.

4

The vulnerability will be discussed in detail at the Objective by the Sea security conference in November.

5

Meta's posts documenting the design decisions for Muse's security and privacy come amid revelations of security breaches in Anthropic and Google models.

Why It Matters

If you're using Meta's Muse AI assistant, your account is vulnerable to a zero-day flaw that lets attackers take full control. The flaw involves changing the transcription endpoint to steal user tokens. Amazon blocked Muse from its site due to the vulnerability, and it will be discussed at the Objective by the Sea security conference in November.

MetaMuseAI assistantzero-day vulnerabilitysecurity breach

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,484 builders reading daily.

Also get