Meta releases patch for Muse macOS zero‑day vulnerability
Meta has released a security update for its Muse macOS application after a zero‑day vulnerability was uncovered that could let an attacker seize control of the AI‑driven assistant. The flaw, identified by security researcher Patrick Wardle, exploited an undocumented Muse setting that permitted locally executed code to reroute transcription data from Meta’s servers to a malicious endpoint, thereby granting the attacker access to the user’s Muse account. The vulnerability required the attacker to have local access to the device, but once exploited it could compromise the cloud‑based dictation workflow that Muse relies on.
The issue stemmed from design choices that allowed Muse’s dictation process to run in the cloud rather than on the device and permitted any application to modify the assistant’s hidden configuration parameters. Meta’s patch disables the undocumented setting and restricts external apps from altering Muse’s core behavior, aiming to prevent similar exploits. The company has advised users to install the update promptly to protect their accounts and ensure the integrity of the AI assistant’s operations.
Read the original at The Verge