Zero-day flaw lets attackers hijack Meta’s Muse via transcription endpoint abuse

1 min read
Source: Ars Technica
Zero-day flaw lets attackers hijack Meta’s Muse via transcription endpoint abuse
Photo: Ars Technica
TL;DR Summary

A zero-day in Meta's Muse AI lets attackers hijack the assistant by manipulating its cloud-based transcription endpoint, enabling any locally run app or terminal command to obtain the Muse authentication token and take full control of the account; security researcher Patrick Wardle demonstrated PoCs that could write files or snap photos, highlighting risky design choices around cloud dictation and broad app privileges. Amazon has begun blocking Muse on its site, and questions about Muse’s security and privacy remain despite Meta’s public statements.

Share this article

Reading Insights

Total Reads

0

Unique Readers

7

Time Saved

7 min

vs 8 min read

Condensed

95%

1,57482 words

Want the full story? Read the original article

Read on Ars Technica