A zero-day vulnerability has been discovered in Meta's recently launched Muse AI assistant, according to infohub.kz.
Security researchers found a flaw in the Muse app for macOS that allows malicious programs to intercept data and gain full access to the account, ArsTechnica reports.
Despite claims by CEO Mark Zuckerberg that the service was designed with security in mind from the start, the flaw in the macOS client lets third-party apps bypass Apple's standard operating system protections.
The issue is that Muse requires users to grant extensive permissions, including writing files to disk, and access to the microphone, camera, location, and calendars. Any process or malicious program running on the device can alter the assistant's hidden settings without additional permissions.
In particular, attackers can redirect traffic containing audio recordings and text queries from Meta's servers to their own resources, and intercept the authorization token to fully compromise the account.
Experts note that the vulnerability nullifies macOS's standard security barriers, creating a risk of covert surveillance and theft of confidential information.
Amid news of the company's security problems, services have begun restricting its operation: in particular, the Amazon marketplace has blocked the use of Muse on its platform.
Meta representatives have not yet publicly commented on the discovered vulnerability.


