Home · Technology · Sep 23 archive

Meta's AI Assistant Muse Hit by Zero-Day Vulnerability

Confirmed

Technology Desk

In Short: Meta's AI assistant Muse, designed to be the brains behind its upcoming smart glasses, has been hit by a serious zero-day vulnerability, raising significant security concerns.

Meta's 'Muse' hits wall with Amazon
YouTube — ABC News

Meta's AI assistant Muse, designed to be the brains behind its upcoming smart glasses, has been hit by a serious zero-day vulnerability, raising significant security concerns.

According to Jane Manchun Wong, a renowned reverse engineer, Meta is testing an option to set Muse as the default assistant for its connected eyewear, indicating the company's plans to integrate the AI deeply into its ecosystem.

YouTube — ABC News YouTube

The vulnerability, disclosed by security researcher Kevin Beaumont, allows any locally installed app or executed code to gain access to the token that authenticates users to their Muse account.

This zero-day flaw was discovered just two weeks after Muse's launch on September 8, and it was patched shortly after its discovery.

The flaw involved Muse's dictation feature, which sends audio to Meta's servers for transcription. An attacker with code running on the user's Mac could redirect this traffic to a server they control, gaining access to the user's audio and Muse account authentication token.

This could potentially allow attackers to hijack the assistant and exploit permissions users have already granted to Muse.

Meta founder Mark Zuckerberg had previously emphasized the security and privacy of Muse, stating it was built from the ground up with these principles in mind.

Amazon also began blocking Muse from its site shortly after the vulnerability was disclosed, citing lack of prior notification and the assistant's inability to identify itself while shopping.

Meta's security team acknowledged the issue, describing it as a local privilege escalation attack that required malicious code already running on the user's machine.

Despite the low practical risk to users of the Muse Mac app, Meta issued a hotfix to address the issue, underscoring the importance of addressing such vulnerabilities promptly.

The vulnerability highlights the broader risks associated with AI assistants that require extensive access to user data and device features.

What this adds

This report adds details about the specific nature of the zero-day vulnerability and its potential impact, as well as Meta's response to the issue. It also highlights the broader security concerns surrounding AI assistants that have access to a wide range of user data and device features.

Background

Meta's new AI assistant, Muse, is drawing both praise and criticism for its capabilities and data collection practices.

What's confirmed

What's still developing

Sources