Researcher finds zero-day flaw in Meta’s Muse AI app

6 sources
  • Security researcher Patrick Wardle published a proof-of-concept exploit showing how an unprivileged local process can hijack Meta Muse's dictation endpoint on macOS.
  • The flaw escalates local malware privileges by exploiting Muse's broad system access, which includes microphone, camera, disk, and calendar permissions on Apple macOS.
  • The disclosure adds to growing scrutiny of Muse, which reviewers say aggressively pushes users to connect email and banking data and once read private notifications unprompted.
Sources (6)
  1. 1 Meta Muse AI app flaw lets local malware redirect dictation traffic www.theregister.com
  2. 2 Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day arstechnica.com
  3. 3 Muse reportedly read private notifications without permission dataconomy.com
  4. 4 Meta Muse: AI assistant doesn't know how it works exactly www.secnews.gr
  5. 5 Meta’s Muse AI agent faces security scare, raises alarms over AI agent safety cryptobriefing.com
  6. 6 It has been pointed out that Meta's AI agent 'Muse' is reading messages that it has not authorized. gigazine.net