Security researcher says don't install Meta's Muse AI assistant

By
Follow google news

Expert "not-a-mused" by insecure AI agent.

Key points

  • Patrick Wardle has published proof-of-concept code for a zero-day, dubbed "not-a-mused", that can turn Meta's Muse AI assistant into a backdoor.
  • An undocumented setting, endo_voyager_dictation_endpoint, can be altered by any local process to redirect dictated audio to an attacker's server.
  • Because Muse holds broad access to files, microphone, camera, location, calendar and even linked iPhones, a compromise could hand an attacker the same reach.
Security researcher says don't install Meta's Muse AI assistant

A prominent macOS security researcher has urged Mac users not to install Meta's new Muse AI assistant, publishing proof-of-concept code for what he described as a zero-day that can turn the app into a ready-made backdoor.

Patrick Wardle, founder of the Objective-See Foundation and author of The Art of Mac Malware, disclosed the flaw in a thread on X accompanied by a working exploit on GitHub.

"Please don't install," he wrote. "It's trivial to turn Muse into the ultimate backdoor."

Wardle called the flaw "not-a-mused".

The problem centres on an undocumented Muse setting, endo_voyager_dictation_endpoint, which Wardle showed could be changed by any local process without elevated privileges.

Once that endpoint is redirected, the audio a user dictates to Muse is sent to an attacker's server instead of Meta's, which the accompanying code says can allow captured prompts, prompt injection into the assistant, and enable theft of its authentication material.

The trigger is mundane, requiring only that a user click the microphone and dictate a prompt as they normally would.

Wardle said the proof of concept is a local attack, one that assumes an attacker can already run code on the machine as the user.

He argues that Muse is a disproportionately valuable target rather than an ordinary one, because an assistant built to manage a Mac holds far broader access than typical malware would arrive with.

To function, Muse asks for reach across files, microphone, camera, location and calendar, so an attacker who hijacks it inherits everything the user has entrusted to it.

"Muse's access can potentially become the attacker's access," the exploit's documentation stated.

A follow-up post extended the concern to linked mobile devices, showing categories of actions that could be requested through a compromised session, including retrieving an iPhone's location, scanning for nearby Bluetooth devices, and accessing information such as contacts, calendars and reminders.

Messaging, by contrast, only prepared a draft rather than sending silently.

Wardle said he would share further detail and further bugs at the Objective by the Sea security conference in November.

Meta has made much of Muse's security, with company founder Mark Zuckerberg promoting the AI assistant as a personal agent that works around the clock on a user's behalf.

The social media giant said the system uses isolated execution, least-privilege access, and a dedicated security layer called Sentinel which Meta described as the sole authority for connector actions, and network egress.

Earlier this year, the viral OpenClaw, then known as Clawdbot, prompted warnings from companies and security researchers over the risks of giving an AI agent broad access to a user's computer, files and accounts.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

ASD says prompt injection in AI cannot be fixed

ASD says prompt injection in AI cannot be fixed

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

Optus may ban smart glasses in stores, offices

Optus may ban smart glasses in stores, offices

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?