Published 13 hours ago • loading... • Updated 2 hours ago
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Security researcher Patrick Wardle said the flaw lets local code redirect dictation traffic and steal authentication tokens, exposing dictated audio and prompts.
On Sunday, Amazon began blocking Meta's new AI assistant, Muse, after security researcher Patrick Wardle discovered a zero-day vulnerability allowing local apps to gain broad access to user data and authentication tokens.
CEO Mark Zuckerberg previously claimed Muse was "built from the ground up for privacy and security," yet the assistant integrates with WhatsApp and calendars, undermining Apple's Transparency, Consent, and Control framework.
By modifying an undocumented setting, attackers can redirect dictation traffic to their own endpoint, stealing authentication tokens and gaining complete control over a user's Muse account and connected services.
Objective-See founder Patrick Wardle likened the vulnerability to a "bad neighbor," stating, "I think some of their greediness for user data kind of opens the door, makes a bigger attack surface."
These companies are "racing for what's next," said Wardle, often neglecting security priorities, while Meta did not immediately respond to requests for comment regarding the privilege escalation vulnerability.