Meta’s new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands to gain complete control over the assistant. This revelation has prompted Amazon to block access to Muse on its platform. Meta CEO Mark Zuckerberg previously touted Muse as being “built from the ground up for privacy and security,” raising questions about the effectiveness of these claims in light of the recent security flaw.
Introduced just weeks ago, Muse is designed to assist users by booking appointments, filling out forms, and handling customer service tasks. The macOS application integrates with various user accounts, including WhatsApp, email, and social media, and can even create tools on the fly when needed. However, to utilize these features, users must grant Muse extensive permissions, including access to sensitive device resources like the microphone and camera.
Security Concerns Arise
The zero-day vulnerability allows any locally installed app or executed code to access the authentication token for Muse accounts. This flaw enables attackers to change critical settings, including the endpoint for transcription services, which typically directs data to Meta’s servers. By redirecting this endpoint to their own servers, attackers can gain full control over a user’s Muse account.
As concerns about Muse’s security grow, the implications for user privacy and data protection are significant. The incident highlights the potential risks associated with granting AI assistants extensive access to personal information and device capabilities. For more details, refer to the full report by Ars Technica.
Follow Cyber Warriors Middle East for further global cybersecurity developments.


