Skip to content
InfoQ·

🚨Meta's Muse Desktop Client Zero-Day Vulnerability Affects macOS

Meta's Muse Desktop Client Zero-Day Vulnerability

TL;DR

Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse desktop client for macOS, enabling local software to hijack the application and bypass macOS security. The vulnerability affects the endo_voyager_dictation_endpoint configuration preference key, allowing for prompt injection attacks and compromising user data.

Security researcher Patrick Wardle has disclosed a zero-day vulnerability in Meta's Muse desktop client for macOS, enabling local software to hijack the application and bypass macOS security boundaries. This vulnerability allows unprivileged software to overwrite the endo_voyager_dictation_endpoint configuration preference key without elevated administrative rights, compromising both input confidentiality and account credentials. When a user activates dictation, the desktop client dispatches raw microphone audio and a valid authentication token to the configured endpoint, making it possible for an attacker to capture authentication tokens and audio data. The vulnerability was demonstrated by a proof-of-concept exploit titled not-a-mused, and Meta deployed a hotfix to strip the internal debugging preference setting from production client builds. This issue highlights the importance of robust security measures in desktop applications and the potential risks associated with platform trust boundaries.

Meta's Muse Desktop Client Zero-Day Vulnerability Affects macOS — InfoQ

Key Points

1

Security researcher Patrick Wardle disclosed a zero-day vulnerability in Meta's Muse desktop client for macOS, enabling local software to hijack the application and bypass security.

2

The vulnerability affects the endo_voyager_dictation_endpoint configuration preference key, allowing unprivileged software to overwrite this key without elevated administrative rights.

3

When a user activates dictation, the desktop client dispatches raw microphone audio and a valid authentication token to the configured endpoint, making it possible for an attacker to capture authentication tokens and audio data.

4

The vulnerability was demonstrated by a proof-of-concept exploit titled not-a-mused, and Meta deployed a hotfix to strip the internal debugging preference setting from production client builds.

5

The community rejects the claim that the issue is a local configuration problem, emphasizing the need for robust security measures in desktop applications.

Why It Matters

If you're using Meta's Muse desktop client on macOS, this vulnerability compromises your security. The endo_voyager_dictation_endpoint configuration preference key allows unprivileged software to overwrite settings without elevated rights, enabling prompt injection attacks and compromising user data. This highlights the importance of robust security measures in desktop applications and the risks associated with platform trust boundaries.

MetaMusemacOSzero-dayvulnerabilityPatrick Wardle

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,496 builders reading daily.

Also get