A zero-day vulnerability in Meta’s Muse AI agent for macOS could allow malware already running under a user account to hijack the assistant, intercept dictated prompts, inject malicious instructions, and steal authentication material. The flaw is especially concerning because a compromised agent could inherit the extensive permissions and connected-service access that users have entrusted to Muse. Security researcher Patrick Wardle, founder of Objective-See, disclosed the issue alongside a proof-of-concept exploit named “not-a-mused.” His research found that Muse exposes an undocumented configuration setting called endo_voyager_dictation_endpoint, which an unprivileged local process can modify without elevated permissions....
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!