Meta fixes security hole that let hackers hijack AI assistant
Meta has patched a vulnerability in its Muse AI app for Mac that could have allowed attackers to take over user accounts. The flaw is now fixed.
Meta has released a security update for its Muse app on macOS after discovering a serious vulnerability. A vulnerability is a hidden weakness in software that hackers can exploit — think of it like an unlocked door in a security system.
Security researcher Patrick Wardle found that someone with access to your computer could trick the Muse AI assistant into sending your voice data to their own server instead of Meta's. This would give them access to your Muse account and everything connected to it. The good news: the attacker needed physical or remote access to your device first — they couldn't do it just by sending you a link or email.
The problem existed because of how Meta designed Muse. When you use voice commands with Muse, your voice gets processed in the cloud (Meta's remote servers) rather than on your device. Additionally, the app allowed other programs running on your Mac to change Muse's hidden settings without asking permission. Hackers exploited this combination to redirect where your data was being sent.
Meta has now patched the issue, which means the vulnerability is fixed. If you use Muse on a Mac, make sure your app is up to date. This is a good reminder that even AI assistants need regular security updates, just like any other software you use.
Original source: The Verge AI
