Meta released Muse, an AI assistant, a few weeks ago, claiming it can handle tasks like booking appointments, filling out forms, and making purchases. The assistant is designed to integrate with users' WhatsApp, email, calendar, and social media accounts. It also creates tools on the fly when needed.

The macOS app, which lacks a Windows version, requires users to grant it access to various device resources, including writing files to disk, accessing the microphone and camera, and monitoring location and calendars. Apple has long restricted these permissions to protect user data, but Muse bypasses these protections entirely.

"We can manipulate the agent and leverage its privileges to do whatever we want," said Patrick Wardle, a macOS security expert who discovered the zero-day.

Wardle explained that attackers could change the transcription endpoint to their own server, gaining full control over the Muse account. He developed proof-of-concept attacks that could write malicious files to disk and take pictures without user awareness.

The vulnerability allows any locally installed app or terminal command to alter a list of undocumented settings, including the transcription endpoint. Meta released a hotfix within 12 hours of the disclosure, but the flaw highlights serious security concerns. Wardle criticized the design choices that enabled the exploit, including cloud-based transcription and allowing apps to control all undocumented settings.

Amazon began blocking Muse from its site shortly before Wardle disclosed the zero-day, citing violations of its Conditions of Use. Amazon stated that third-party applications must operate openly and respect service provider decisions. Meta has yet to explain why it used cloud-based transcription instead of macOS's on-device option.

The flaw dismantled Apple's security architecture, which has taken years to develop. Meta's response did not address how easily ClickFix attacks could trigger the exploit, despite being asked to do so. The incident raises questions about how much effort was invested in securing Muse.

Source: wired