Zero-day flaw lets attackers hijack Meta’s Muse via transcription endpoint abuse

TL;DR Summary
A zero-day in Meta's Muse AI lets attackers hijack the assistant by manipulating its cloud-based transcription endpoint, enabling any locally run app or terminal command to obtain the Muse authentication token and take full control of the account; security researcher Patrick Wardle demonstrated PoCs that could write files or snap photos, highlighting risky design choices around cloud dictation and broad app privileges. Amazon has begun blocking Muse on its site, and questions about Muse’s security and privacy remain despite Meta’s public statements.
- Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day Ars Technica
- Meta's Muse AI agent downloads are surging. Here's how it compares to ChatGPT, Grok and Claude CNBC
- Meta’s New AI Agent Could Be the Missing Piece for META Stock Yahoo Finance
- Meta’s New Muse AI App Tops Charts, Draws Strong Reviews Bloomberg.com
- Meta’s Muse TV ad is the latest sign that AI agents are going mainstream Business Insider
Reading Insights
Total Reads
0
Unique Readers
7
Time Saved
7 min
vs 8 min read
Condensed
95%
1,574 → 82 words
Want the full story? Read the original article
Read on Ars Technica