律动BlockBeats
律动BlockBeats|Sep 22, 2026 03:38
[Muse Exposed to Zero-Day Vulnerability, Local Program Can Hijack Agent Permissions] Beating AI News Flash: Meta's personal AI Agent, Muse, was launched just two weeks ago, but security researcher Patrick Wardle has already uncovered a local zero-day vulnerability. If an attacker can execute a piece of code on a Mac under the current user's identity, they can modify a hidden setting in Muse to redirect voice requests to their own server. This code does not require additional macOS permissions. Subsequently, the attacker could intercept what the user says to Muse, inject malicious commands, and potentially obtain Muse's authentication credentials. Muse itself has access to system resources like files and the camera. Any permissions granted to Muse by the user could be exploited by malicious programs through Muse. However, this is not a vulnerability that allows remote attacks on Macs; the attacker must first execute the code locally. When Meta released Muse, it specifically emphasized its security design, including the addition of Muse Secure VM and an independent Sentinel Agent. Unexpectedly, the first zero-day vulnerability stems from a hidden setting in the Mac client that can be modified by a standard local process. [Original Link]
+4
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads