Back to Home
The Verge AI··Industry Media

Meta patches Muse exploit that let attackers control the AI agent

中文摘要

Meta 修复了 Muse macOS 应用的零日漏洞,攻击者可通过本地访问重定向转录,从而控制 AI 代理账户。

English Summary

Meta patched a Muse macOS zero-day vulnerability that allowed attackers with local access to hijack AI agent accounts by redirecting transcription processing.

Original Excerpt

The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta's servers to their own endpoint, Ars Technica reports, giving the attacker access to the Muse account. Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse's undocumented settings. Pr … Read the full story at The Verge.