Crypto Ticker:
sysadmin from Cyber Security News

Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware

Guru Baran
5 hours ago
5 Views
0 Comments
Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware

A zero-day vulnerability in Meta’s Muse AI agent for macOS could allow malware already running under a user account to hijack the assistant, intercept dictated prompts, inject malicious instructions, and steal authentication material. The flaw is especially concerning because a compromised agent could inherit the extensive permissions and connected-service access that users have entrusted to Muse. Security researcher Patrick Wardle, founder of Objective-See, disclosed the issue alongside a proof-of-concept exploit named “not-a-mused.” His research found that Muse exposes an undocumented configuration setting called endo_voyager_dictation_endpoint, which an unprivileged local process can modify without elevated permissions....

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!