Meta's Muse AI assistant faces critical zero-day vulnerability

Meta's recently launched AI assistant, Muse, is facing significant scrutiny following the discovery of a critical zero-day vulnerability. Despite Meta CEO Mark Zuckerberg's claims that the assistant was built with privacy and security as core priorities, the flaw allows locally run applications and terminal commands to gain unauthorized control over the agent. Muse is designed to handle sensitive tasks, including booking appointments, making purchases, and managing email and social media accounts, requiring extensive system permissions on macOS. Security researchers have raised concerns that the assistant effectively bypasses Apple's built-in security protections, granting access to restricted resources like the microphone, camera, and file system. The severity of the issue has already prompted Amazon to block Muse from its platform. This incident highlights the risks associated with granting high-level system privileges to AI agents that operate with broad autonomy across a user's digital life.
This is a summary. Read the full article at the original source:
Ars TechnicaRelated stories
Researchers demonstrate InjectEave: A technique to intercept audio through walls
Researchers from HKUST (Guangzhou) and HK PolyU have unveiled 'InjectEave,' a sophisticated eavesdropping technique capable of extracting audio from h…
The article discusses an innovative approach to digital content authentication, proposing the use of 'spymarks' as a superior alternative to tradition…
Cybersecurity researchers at Zimperium have identified a sophisticated new Android malware strain dubbed RatHat. Unlike traditional malware that relie…


