Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
· Source: Ars Technica AI
Meta recently unveiled Muse, an AI assistant for macOS that claims to handle scheduling, form filling, customer support, and online purchases, among other tasks. The company emphasized that the tool was built “from scratch for privacy and security,” yet its operation requires users to grant extensive permissions for email, calendars, social media, microphone, camera, location, and file‑system access. According to the report, a zero‑day vulnerability allows local applications and terminal commands to take full control of the assistant, bypassing the safeguards Apple embeds in its operating system to prevent installed programs from accessing critical resources. This flaw endangers the personal and professional data that Muse can reach, potentially enabling data manipulation, interception of communications, or execution of unauthorized actions. In response, Amazon has begun blocking access to Muse from its website, indicating that the vulnerability has already raised concerns among third parties. The incident is significant because it shows that, despite security promises, AI assistants can introduce new attack vectors that compromise user privacy and force a reassessment of the trust placed in emerging technologies.
Read the original article on Ars Technica AI
This summary is an informational synthesis produced by dataqbs.com. All rights to the original content belong to its author and the cited media outlet. We act solely as curators of technology news and claim no authorship.