One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Overview
A security vulnerability has been discovered in Meta's Muse assistant that could allow malware already on a Mac to hijack the assistant. Researcher Patrick Wardle demonstrated that by modifying a hidden setting, attackers could redirect voice commands meant for Muse to themselves. This means that any sensitive information users dictate could be intercepted by malicious actors. The issue stems from the broad permissions granted to the Muse app, which can be exploited if the malware is already present on the device. This incident raises concerns about the security of AI assistants and the potential for them to be weaponized against users.
Key Takeaways
- Affected Systems: Meta Muse assistant on macOS
- Action Required: Users should ensure that their devices are free from malware and review app permissions, particularly for voice assistants.
- Timeline: Disclosed on September 21, 2023
Original Article Summary
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta. The flaw is in
Impact
Meta Muse assistant on macOS
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Disclosed on September 21, 2023
Remediation
Users should ensure that their devices are free from malware and review app permissions, particularly for voice assistants. Regular software updates and security scans are recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Vulnerability, Malware, Meta.