Technology 3 min read source: Ars Technica Türkçe

Serious Zero-Day Vulnerability Discovered in Meta's AI Assistant Muse

A zero-day vulnerability found in Meta's new AI assistant Muse allows locally run apps and terminal commands to gain complete control over the agent.

Serious Zero-Day Vulnerability Discovered in Meta's AI Assistant Muse
Image: Ars Technica

A critical zero-day vulnerability has been identified in Meta's recently introduced AI assistant, Muse, allowing locally running applications and terminal commands to gain full control over the assistant. Discovered by macOS security expert Patrick Wardle, this flaw raises serious questions about Meta CEO Mark Zuckerberg's claims that Muse was "built from the ground up for privacy and security."

The vulnerability enables attackers to gain access to the authentication token that grants users access to their Muse accounts. This could allow malicious actors to exploit Muse's extensive permissions to access user data and perform various actions. Additionally, Amazon has begun blocking Muse from making purchases on its site as of Sunday.

Highlights

  • Zero-Day Flaw: A critical vulnerability was found in Muse, allowing local apps or terminal commands to access the assistant's authentication token.
  • Complete Control: The flaw enables attackers to fully hijack the Muse account and leverage the assistant's privileges to perform any desired actions.
  • Design Flaws: Security expert Patrick Wardle attributes the vulnerability to Meta developers' design decisions, such as choosing cloud-based dictation and allowing any app to control undocumented settings.
  • Amazon Block: Amazon has blocked Muse from making purchases on its platform, labeling the assistant an "unauthorized AI agent" that violates its conditions of use.
  • Privacy Concerns: Muse's need for extensive access to user data, including WhatsApp, email, calendar, and social media accounts, raises significant privacy concerns, especially in light of this security flaw.

Details

Meta's Muse, introduced a few weeks ago, is designed to perform various tasks such as booking appointments, filling out forms, handling customer service, making purchases, generating images, and creating documents. To function, Muse requires users to grant it broad access to personal data, including email, calendar, and social media accounts, as well as macOS operating system permissions (e.g., writing files to disk, accessing the microphone/camera, monitoring location). Apple's long-standing security measures to prevent unauthorized access to such resources are effectively bypassed by Muse's design.

The discovered zero-day vulnerability allows any locally installed app or terminal command to gain access to the authentication token for a Muse account. Meta developers designed the assistant so that any locally executed code, regardless of its macOS permissions, could modify a long list of undocumented settings. One crucial setting allows processes to change the endpoint where transcription occurs. Attackers can exploit this flaw by redirecting this endpoint to their own server, thereby obtaining the token that grants complete control over the Muse account.

Patrick Wardle points out that Meta's design choices, such as opting for cloud-based dictation and allowing any app to control all undocumented settings, made this exploit possible. According to Wardle, the security bar for such AI applications should be significantly higher, but Muse's design appears to have overlooked fundamental security considerations.

Why it matters

Security vulnerabilities in AI assistants like Muse, which require extraordinary access to user data and system resources, pose significant risks to user privacy and data security. Such flaws could enable malicious actors to easily access personal information, financial data, and other sensitive details. This situation highlights the critical importance of meticulously addressing the security and privacy aspects of rapidly evolving AI technologies.

Technology

← All news