Meta patches Muse exploit that let attackers control the AI agent
摘要
Meta已为macOS版Muse应用发布补丁,修复一个零日漏洞。该漏洞由安全研究员Patrick Wardle发现,需本地访问设备,但可让攻击者控制Muse账户。漏洞利用未公开的Muse设置,将转录处理从Meta服务器重定向至攻击者端点。据报道,云端听写及任意应用可控制未公开设置等设计决策导致了该缺陷。
Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta's servers to their own endpoint, Ars Technica reports, giving the attacker access to the Muse account.
Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse's undocumented settings. Pr …
转载信息
评论 (0)
暂无评论,来留下第一条评论吧