Meta patches zero-day flaw in Muse app that allowed AI agent hijacking

Meta has released a security patch for its Muse macOS app after a zero-day vulnerability was discovered by researcher Patrick Wardle. The flaw exploited an undocumented setting in Muse that allowed attackers with local device access to redirect transcription processing from Meta's servers to their own endpoint. This gave attackers effective control over the victim's Muse account. Several design choices contributed to the vulnerability, including cloud-based dictation processing and the ability for any app to modify Muse's hidden settings. The patch addresses these issues following responsible disclosure of the exploit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in