Meta has been keen to tout the privacy and security features of its latest AI assistant, Muse. However, a zero-day vulnerability has emerged that undermines these claims. The issue allows any locally run app or terminal command to gain full control of the assistant, casting serious doubt over its supposed security measures.
Introducing Muse, which handles tasks such as booking appointments and filling out forms, Meta initially presented it as a secure and user-friendly tool. But the zero-day flaw reveals that, despite these assurances, the app can be manipulated to access sensitive information and potentially run malicious code. This is particularly concerning given that the macOS version of the app requires extensive permissions, including access to the microphone, camera, and location data.
Further complicating matters, the vulnerability could allow attackers to change the endpoint where transcription occurs, potentially redirecting sensitive data to unauthorized servers. Meta's developers appear to have overlooked this critical security measure, which could have significant ramifications for users' privacy and data security.
It remains to be seen how Meta will address this issue. The company's decision to block Muse from Amazon's site on Sunday adds a layer of mystery to the situation, prompting questions about the severity and impact of this zero-day vulnerability. As AI assistants become more ubiquitous, such incidents highlight the ongoing challenges in ensuring robust security for these technologies.







