Meta’s Artificial Intelligence (AI) assistant Muse reportedly carried a zero-day vulnerability that could let attackers access connected applications, including WhatsApp and email.
Security researcher Patrick Wardle, founder of nonprofit Objective-See, discovered the flaw and named it “not-a-mused.” It is linked to an undocumented setting called endo_voyager_dictation_endpoint, which lets users change where voice dictation is processed. Muse normally sends voice commands to the cloud, where Meta can log them.
The attack requires several conditions. Muse must already be connected to other applications, voice dictation must be enabled, and an attacker must have local access to change the setting. That access could come through remote monitoring and management tools, low-level malware, or physical access.
With those conditions in place, voice commands could be redirected to attacker-controlled infrastructure along with authentication tokens. An attacker could then use Muse’s access to request sensitive information from connected applications. Wardle told Ars Technica that he developed proof-of-concept attacks capable of writing malicious files to disk and taking pictures, sometimes without an obvious alert.
Meta has been informed but has not commented or issued a patch, according to the report.
Comments
0No comments yet. Be the first to comment.