UK Regulator Ofcom Investigates Meta Over Risks of New Instagram Feature
Read more
Olhar Digital
olhardigital.com.br

UK Regulator Ofcom Investigates Meta Over Risks of New Instagram Feature

The UK regulator Ofcom has launched an investigation to determine whether Meta complied with UK online safety rules before launching the Instagram Instants feature. This feature allows users to share images that disappear after viewing.

The review aims to establish whether the company conducted a proper risk assessment concerning illegal content and potential impact on children before rolling out the tool in May.

Instants enables sending photos to friends or people the user follows who also follow them. After viewing, the pictures disappear. For teenagers with Teen accounts, Meta claims to provide protections such as screenshot blocking, sharing, and forwarding.

This specific change to the service is at the center of the investigation. Under British law, significant changes to digital platforms must undergo an assessment before launch. Ofcom seeks to determine if Meta met this requirement in the case of Instants.

The analysis also covers risks associated with content types such as pornography, self-harm, suicide, violence, hate speech, and bullying. The regulator has previously pointed out that messaging and disappearing image features can pose dangers to children and adolescents.

Meta stated that it takes its obligations under British law seriously. In a statement, the company reported that it conducted a risk analysis and informed Ofcom about the feature prior to its launch.

A Meta representative stated: 'We conducted a risk assessment and informed Ofcom about this feature on several occasions before its launch.' The company also emphasized: 'Naturally, we will cooperate with Ofcom during this investigation.'

Instants functions similarly to tools available on platforms like Snapchat and WhatsApp, which allow sending photos that can disappear after being viewed.

Ofcom began the process by collecting and analyzing evidence to determine if any legislation was violated. If the regulator decides that Meta failed to meet its obligations, it will issue a preliminary decision to the company, which it can respond to before the investigation concludes.

More details:

If a violation is confirmed, Ofcom may require measures to bring the platform into compliance with the law and compensate for any potential damages. Furthermore, the regulator could impose a fine of up to £18 million (approximately 132 million Brazilian reais) or 10% of the company's global annual turnover, whichever is greater.

The investigation takes place amid ongoing legal proceedings where Meta, TikTok, and X are challenging certain requirements set by Ofcom regarding the application of the UK Online Safety Act.

Similar stories

Meta launches camera-free smart glasses, Ray-Ban Meta Audio, in response to privacy concerns
Read more
olhardigital.com.br

Meta launches camera-free smart glasses, Ray-Ban Meta Audio, in response to privacy concerns

On Wednesday, the 23rd, during the Connect 2026 conference, Meta unveiled its first smart glasses equipped with artificial intelligence (AI) and devoid of a camera. These new devices, named Ray-Ban Meta Audio, were designed to mitigate concerns raised about the more controversial uses of the company's AI glasses.

Unlike other models offered by the company, the Ray-Ban Meta Audio operate solely with audio functionalities. They allow users to listen to music and podcasts, make calls, translate speech, and interact with Meta's AI assistant, known as Muse.

The development of this product was carried out in collaboration with EssilorLuxottica, Meta's partner in AI-focused hardware projects. The initial price set for the device is US$ 349 (equivalent to R$ 1,850).

Statement on the new product category

Meta CEO Mark Zuckerberg commented during the presentation that after developing the idea, the company identified the possibility of creating a new line of products centered on audio glasses. He asked the public: 'Once you get used to high-quality audio, it's simply something you want all the time, right?'

The decision to eliminate cameras also helped Meta design a thinner device compared to its previous models. The Ray-Ban Meta Audio weighs 43 grams and includes adjustable arms, replaceable nose pads, and hinges with protection against excessive stretching.

Battery life can reach 12 hours on a single charge, according to Meta. When used with the provided charging case, this duration can be extended up to 48 hours. The glasses will be available in various color options and combinations, totaling 23 color and lens arrangements, in addition to two new frame designs.

Among the new styles are the Clubmaster, which recalls the retro look of Ray-Ban models, and the Burbank, characterized as a classic and timeless rectangular frame. As with other Meta smart glasses, the Ray-Ban Meta Audio can be ordered with corrective lenses, if necessary.

Pre-sales of these glasses will begin on October 13th.

Next Generation with Camera

In addition to the camera-free glasses, Meta also presented the next version of its smart glasses equipped with a camera, the Ray-Ban Meta (Gen 3). This line will maintain the Ray-Ban Meta Wayfarer model and introduce two new styles: Aviator and Zena, the latter featuring a frame shape closer to a cat-eye style.

The renewed models will feature a 12 MP camera capable of recording videos in 3K Ultra HD resolution, along with a six-microphone system and a battery that lasts up to nine hours. The glasses, developed by Meta in partnership with EssilorLuxottica, will also receive an increase in the variety of available colors and styles.

The company also announced a new collaboration with singer Lisa, following a previous work with Kylie Jenner. Meta reported that the glasses will be launched in more countries globally. All of Meta's AI smart glasses will have access to Muse, the company's new AI personal assistant.

Meta anticipated several features that will be implemented in the devices. Innovations include Dolby Atmos Capture, a function that selects the best image among multiple captured frames, and the option to choose between landscape and portrait formats. The company is also working on auditory enhancement features for people with hearing impairments, more detailed responses, different audio modes, and customizable controls.

Another highlighted feature is the so-called 'private processing,' which, according to Meta, prevents the company itself from accessing user data.

Meta's new AI assistant, Muse, has critical security flaw on Mac devices
Read more
olhardigital.com.br

Meta's new AI assistant, Muse, has critical security flaw on Mac devices

Muse, Meta's newly launched artificial intelligence (AI) personal assistant, was targeted by a zero-day vulnerability discovered just weeks after its release. This flaw had the potential to allow an attacker to take control of the assistant on a Mac computer and use its inherent privileges to execute actions on the system.

The discovery was made by macOS security expert Patrick Wardle, who issued an alert about the issue. According to the researcher, an attacker could exploit the permissions that Muse requires to modify a setting related to the voice transcription system.

Normally, the application sends the transcription to a server managed by Meta. However, due to the flaw, the destination address could be swapped for a server controlled by the attacker. This would enable the acquisition of the token responsible for authenticating the Muse account.

With this token in hand, the aggressor would not necessarily need to install specific malicious software to steal data. Instead, they could directly take over the assistant itself, leveraging the privileges Muse already possesses on the computer.

One of the methodologies demonstrated by Wardle involves a variation of the technique known as ClickFix, a form of social engineering used to convince users to execute commands on their devices. In this scenario, a server controlled by the attacker would act as an intermediary between Muse and Meta's server. After the user provides a voice command, the malicious server could inject an instruction for the assistant to perform a harmful action.

As an example, Ars Technica cited the possibility of sending a file containing all WhatsApp messages to the attacker. Furthermore, the Muse authentication token would be transmitted to the malicious server, ensuring the attacker maintains control over the assistant's account.

Wardle emphasizes that the attack is particularly alarming because it exploits the AI agent itself, eliminating the need to develop dedicated data collection software. He told Ars Technica: 'We can manipulate the agent and leverage its privileges to do whatever we want.'

More information about the vulnerability

The researcher points out that one of the design decisions that facilitated the attack was Meta's choice to process voice transcription in the cloud. The macOS operating system has native features for dictation and transcription directly on the device. In Wardle's analysis, if Meta had chosen this alternative, the demonstrated attack would not be viable.

Another point raised relates to the ability of applications to control undocumented Muse settings. While some of these settings have minor detrimental functions, one specifically allows changing the address used for processing transcriptions. The combination of these two choices opened a path for a local command or application to modify the destination of sensitive information processed by the assistant.

Following the disclosure of the flaw, Meta announced that it had released a hotfix to resolve the issue, and this update was made available approximately 12 hours after Wardle published the details. The company also classified the vulnerability as one that could not be exploited remotely. However, Ars Technica noted that a variation of ClickFix attacks could be employed to persuade a user to execute the necessary code on their own computer.

Prior to the fix, Meta had promoted Muse as an assistant designed from the outset with a focus on security and privacy. The company implemented Muse Secure VM, an isolated virtual environment where the agent was supposed to operate with specific protections. The company claims that this environment was designed to provide protection, security, and privacy mechanisms while Muse performs tasks on behalf of the user.

The discovery of the vulnerability coincided with the moment Amazon began preventing Muse from making purchases on its platform. Users attempting to use the assistant to acquire products received a notification stating that Muse was an unauthorized AI agent and violated Amazon's terms of service. Amazon also asked Meta to remove the platform from its shopping experience, asserting that third-party applications making purchases on behalf of consumers must operate transparently and respect service decisions regarding their participation in such interactions.

Muse was introduced by Meta in early September and is currently available for macOS, but there is no version for Windows. The original article about Meta's new AI assistant facing a serious security flaw that could put Mac users at risk was initially published in Olhar Digital.

Popular