Interestana
Home/News/Meta Muse AI Assistant Vulnerable to Backdoor Takeover
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Meta Muse AI Assistant Vulnerable to Backdoor Takeover

Meta Muse AI Assistant Vulnerable to Backdoor Takeover

Malware already present on a user's Mac can exploit a hidden configuration setting within Meta's Muse AI assistant to redirect prompts to attackers, according to security researcher Patrick Wardle. Wardle demonstrated this vulnerability in a proof-of-concept released on September 21, showcasing how an attacker could effectively turn the AI assistant into a backdoor into the user's system. The exploit works by altering a specific, concealed setting within the Muse application. When a user activates the microphone and dictates a prompt, intending to interact with the AI, the altered setting diverts the audio input. Instead of the prompt being processed by Meta's AI services, it is sent directly to the attacker. This bypasses the intended functionality of Muse and allows malicious actors to intercept potentially sensitive information.

The core of the vulnerability lies in the broad permissions that users often grant to AI assistants like Muse. These permissions typically include access to microphone input, and in some cases, broader system access to facilitate more integrated user experiences. By hijacking the prompt input, attackers can leverage these existing permissions for their own purposes. This means that any data the user intended to share with Muse for legitimate tasks, such as setting reminders, searching for information, or controlling smart home devices, could be intercepted and misused. The proof-of-concept highlights a critical security oversight that could have significant implications for user privacy and data security on macOS devices.

Wardle's research underscores the importance of scrutinizing application permissions and the potential for subtle configuration changes to create severe security risks. While Muse is designed to be a helpful assistant, this vulnerability transforms it into a potential conduit for unauthorized data access. The exploit targets a specific hidden setting, suggesting that attackers could automate the process of compromising Muse installations on infected machines. The implications extend beyond simple prompt interception; depending on the user's granted permissions and the nature of the intercepted prompts, attackers could gain insights into personal conversations, sensitive queries, or even commands that could further compromise the system. The demonstration serves as a stark reminder of the evolving threat landscape in AI-powered applications and the need for continuous security vigilance from both developers and users.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next