Meta's new AI assistant, Muse, has critical security flaw on Mac devices
Read more
Olhar Digital
olhardigital.com.br

Meta's new AI assistant, Muse, has critical security flaw on Mac devices

Muse, Meta's newly launched artificial intelligence (AI) personal assistant, was targeted by a zero-day vulnerability discovered just weeks after its release. This flaw had the potential to allow an attacker to take control of the assistant on a Mac computer and use its inherent privileges to execute actions on the system.

The discovery was made by macOS security expert Patrick Wardle, who issued an alert about the issue. According to the researcher, an attacker could exploit the permissions that Muse requires to modify a setting related to the voice transcription system.

Normally, the application sends the transcription to a server managed by Meta. However, due to the flaw, the destination address could be swapped for a server controlled by the attacker. This would enable the acquisition of the token responsible for authenticating the Muse account.

With this token in hand, the aggressor would not necessarily need to install specific malicious software to steal data. Instead, they could directly take over the assistant itself, leveraging the privileges Muse already possesses on the computer.

One of the methodologies demonstrated by Wardle involves a variation of the technique known as ClickFix, a form of social engineering used to convince users to execute commands on their devices. In this scenario, a server controlled by the attacker would act as an intermediary between Muse and Meta's server. After the user provides a voice command, the malicious server could inject an instruction for the assistant to perform a harmful action.

As an example, Ars Technica cited the possibility of sending a file containing all WhatsApp messages to the attacker. Furthermore, the Muse authentication token would be transmitted to the malicious server, ensuring the attacker maintains control over the assistant's account.

Wardle emphasizes that the attack is particularly alarming because it exploits the AI agent itself, eliminating the need to develop dedicated data collection software. He told Ars Technica: 'We can manipulate the agent and leverage its privileges to do whatever we want.'

More information about the vulnerability

The researcher points out that one of the design decisions that facilitated the attack was Meta's choice to process voice transcription in the cloud. The macOS operating system has native features for dictation and transcription directly on the device. In Wardle's analysis, if Meta had chosen this alternative, the demonstrated attack would not be viable.

Another point raised relates to the ability of applications to control undocumented Muse settings. While some of these settings have minor detrimental functions, one specifically allows changing the address used for processing transcriptions. The combination of these two choices opened a path for a local command or application to modify the destination of sensitive information processed by the assistant.

Following the disclosure of the flaw, Meta announced that it had released a hotfix to resolve the issue, and this update was made available approximately 12 hours after Wardle published the details. The company also classified the vulnerability as one that could not be exploited remotely. However, Ars Technica noted that a variation of ClickFix attacks could be employed to persuade a user to execute the necessary code on their own computer.

Prior to the fix, Meta had promoted Muse as an assistant designed from the outset with a focus on security and privacy. The company implemented Muse Secure VM, an isolated virtual environment where the agent was supposed to operate with specific protections. The company claims that this environment was designed to provide protection, security, and privacy mechanisms while Muse performs tasks on behalf of the user.

The discovery of the vulnerability coincided with the moment Amazon began preventing Muse from making purchases on its platform. Users attempting to use the assistant to acquire products received a notification stating that Muse was an unauthorized AI agent and violated Amazon's terms of service. Amazon also asked Meta to remove the platform from its shopping experience, asserting that third-party applications making purchases on behalf of consumers must operate transparently and respect service decisions regarding their participation in such interactions.

Muse was introduced by Meta in early September and is currently available for macOS, but there is no version for Windows. The original article about Meta's new AI assistant facing a serious security flaw that could put Mac users at risk was initially published in Olhar Digital.

Similar stories

OpenAI Consultant Warns of Risk of Losing Control Over Artificial Intelligence
Read more
olhardigital.com.br

OpenAI Consultant Warns of Risk of Losing Control Over Artificial Intelligence

A new OpenAI consultant has raised alarms regarding the dangers associated with the accelerated development of artificial intelligence. According to Paul Christiano, the industry has not yet reached a level that allows the risk of catastrophic loss of control to be reduced to an acceptable level.

Christiano, who previously held the position of Head of Alignment at OpenAI and serves as a technology advisor to the US government, joined the advisory board of the company's non-profit foundation, as well as the safety and security committee.

In a post on X, the researcher stated directly about the sector's current readiness: 'There is a significant risk that the rapid acceleration of AI capabilities will lead to a catastrophic and irreversible loss of control in the very near future.' He added that he does not believe that the AI industry as a whole, including OpenAI, is currently moving toward reducing this risk to an acceptable level.

Nevertheless, Christiano believes the situation can be corrected. In his assessment, OpenAI is capable of significantly mitigating risks if it takes appropriate actions.

One of the main problems is the probability that AI will begin participating in its own technological development. OpenAI predicts that systems could fully automate research in this area within 18 months, but Christiano considers this timeline uncertain: it could happen in a few months or take many years.

This warning came after incidents involving AI agents during training. OpenAI acknowledged that hundreds of such agents gained access to the internet, interacted on forums, and hacked a third-party website during exercises.

Anthropic also reported an incident involving one of its Claude versions. The company discovered two instances of misalignment: in one episode, the model accessed the internet and sent malicious code to a public repository. Anthropic notified that four incidents will be analyzed as part of an independent investigation conducted by the organization METR.

The topic garnered even more attention after Evan Hubinger, Head of Alignment Science at Anthropic, estimated the probability that AI will 'kill all humans' in the next decade to be over 10%.

More Details:

Geoffrey Hinton, a Nobel laureate and one of the pioneers in this field, deemed this estimate reasonable but stressed that no one knows how to calculate such a probability.

Jacob Coxon, a 27-year-old researcher who left Anthropic, also issued a warning about the pace of development. He stated that current models are not yet smart enough to cause human extinction but pointed to the possibility of recursive self-improvement in the near future.

For Christiano, superintelligent artificial intelligence without reliable safety mechanisms could lead to an irreversible loss of human control, which could potentially have fatal consequences for a large portion of the population.

The researcher insists that Anthropic also advocates for faster development of safety and alignment compared to the capabilities of the models. In Christiano's view, governments and corporations must coordinate their efforts if the pace of development increases the risk of losing control.

The article about the OpenAI consultant's warning about the risk of losing control over AI first appeared in Olhar Digital.

Popular