Meta's Muse AI assistant has a serious 0-day vulnerability
macOS security expert Patrick Wardle discovered a 0-day in Meta's Muse AI assistant that lets any local app or terminal command steal the token authenticating users to their Muse account. Amazon also began blocking Muse from shopping on its site, calling it an unauthorized AI agent.
- The flaw lets any local app or terminal command hijack the Muse account token
- Attack works via cloud transcription and an undocumented endpoint setting
- Amazon blocks Muse as an 'unauthorized AI agent' violating its Conditions of Use
- Meta did not respond to questions despite recent posts touting Muse privacy
Read next
Security