Researcher finds zero‑day that hands attackers control of Meta's Muse
Patrick Wardle said any local app can steal the token that controls a Muse account. Meta did not answer questions from Ars Technica.
Any app or terminal command running on a Mac can seize control of a user's Muse account, the security researcher Patrick Wardle told Ars Technica. Meta released the assistant a few weeks ago. Wardle said he has written several working proof-of-concept attacks against it.
The flaw sits in a list of undocumented settings that Meta lets any local process change, according to Wardle. Most control cosmetic things such as dark mode. One sets the server address where Muse sends speech for transcription, and pointing it at an attacker's machine hands over the account token.
"We can manipulate the agent and leverage its privileges to do whatever we want," Wardle said. He said the attacks can write files to disk and take photographs with no sign to an alert user. A variant of the ClickFix technique is enough to start one.
Meta has published two posts in as many weeks on the design decisions behind Muse, and Mark Zuckerberg has said the assistant is built from the ground up for privacy and security. Meta representatives did not answer emailed questions, Ars Technica said.
Wardle said Muse could have avoided the flaw by transcribing speech on the device, as macOS allows, rather than in Meta's cloud. The account rests on Wardle's own testing, and Meta has not said whether it plans a fix. He may give more detail at a conference in November.