Local Malware Exploited Hidden Config File to Hijack Meta AI Assistant Tokens
Security researcher Patrick Wardle discovered that local malware could silently alter an undocumented preference file in Meta's AI voice assistant to redirect its communication to an attacker-controlled server. This allowed the malware to inject trusted instructions and steal an authentication token linked to the user's account. Because the token was not scoped to a single device, attackers could gain persistent access to chat history, location data, and smart-home controls across every device tied to the same account. The core vulnerability was not an AI-specific flaw but a classic config-hijacking technique applied to a client holding unusually broad, cross-device credentials. Security experts warn that any locally writable configuration file influencing a trusted connection must be threat-modeled as rigorously as a public-facing API.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in