Technologies
Back
Cybersecurity & Privacy

Meta Muse security: a Mac zero-day and a 6.8 GB filesystem export

Dev.to
Advertisement468 × 90
Meta Muse security: a Mac zero-day and a 6.8 GB filesystem export

Meta's new AI agent, Muse, is facing significant scrutiny following two major security findings. Security researcher Patrick Wardle disclosed a zero-day vulnerability in the macOS application that allows any local process to redirect voice transcription endpoints, effectively granting an attacker full control over the user's account token. Separately, developer Peter James demonstrated that the agent could be manipulated into exporting its entire 6.8 GB Linux sandbox filesystem upon request, revealing internal manuals, sub-agent transcripts, and unreleased connector configurations. Despite these findings, Meta has reportedly marked the export issue as 'Not Applicable' and has not provided a public patch. These incidents highlight critical risks for AI agents that require extensive system permissions, as they can bypass traditional security boundaries. Experts advise that developers must treat all local settings as potential inputs and ensure that sensitive credentials remain protected from unauthorized runtime overrides.

This is a summary. Read the full article at the original source:

Dev.to
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250