跳到主要內容
AI News HubLIVE
來源內容 · 翻譯待補全2 分鐘閱讀

待翻譯:Meta patches Muse exploit that let attackers control the AI agent

文章摘要

AI 服務暫時不可用,以下為來源摘要,待恢復後補全翻譯:The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta's servers to their own endpoint, Ars Technica reports, giving the attacker access to the Muse account. Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse's undocument…

來源The Verge AI作者: Jess Weatherbed
待翻譯:Meta patches Muse exploit that let attackers control the AI agent
回報錯誤

更正管道尚未開通,可先複製下方文章資訊留存。

查看更正說明
直接讀正文

AI 服務暫時不可用,以下為來源正文,待恢復後補全翻譯。

Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta’s servers to their own endpoint, Ars Technica reports, giving the attacker access to the Muse account. Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse’s undocumented settings. Proof-of-concept attacks developed by Wardle to test the exploit enabled him to take pictures and write malicious files to disk via Muse, which did not alert the user in many cases. “We can manipulate the agent and leverage its privileges to do whatever we want. So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself,” Wardle told Ars Technica. “At the very least, they should be thinking about security from the very start, and they are just not.” That stands in contrast with the emphasis that Meta placed on Muse’s privacy and security features when it announced the AI agent earlier this month. Meta patched the vulnerability in the hours following the Ars report being published, and asserts that real-world security concerns were minimal because the exploit required local access to the user’s device. “This was a local privilege escalation attack, not a remote exploit. Using it to do harm therefore requires malicious code already running on the user’s machine under their user account and the practical risk to users of the Muse Mac app was therefore quite low,” David Singleton of Meta Superintelligence Labs said on X. “Nonetheless, we have issued a hotfix to the app to address the issue.” While quickly addressed, the Muse exploit comes at a time when Meta’s AI agent is already being scrutinized as the company tries to claw back ground from rival AI providers. Amazon recently blocked Muse from accessing its e-commerce platform and claims Meta never obtained its permission to do so. Still, the launch has been successful for Meta — during its first 12 days, estimated downloads of the Muse mobile app have reportedly outpaced ChatGPT’s own 12-day debut in the US and Canada, with Meta stock climbing by 11 percent on Monday.

展開要點與分析

文章情報

工程師進階

要點

  • AI 服務暫時不可用,系統已先保留來源內容與降級後設資料。
  • The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macO…

技術影響

可能影響 Agent 架構、工具呼叫、工作流自動化和產品整合。

要點與分析由自動化流程生成,可能有誤,請結合原始來源核實。