Meta's Muse AI Assistant Vulnerability Enables Mac Hijacking

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Meta's Muse AI assistant for macOS contains a zero-day vulnerability that allows attackers to hijack user accounts and gain full control over Macs. The flaw, discovered by security researcher Patrick Wardle, stems from Muse's privileged permissions and design, leading to unauthorized access and potential harm. Amazon has blocked Muse from its platform.[AI generated]

Why's our monitor labelling this an incident or hazard?

The AI system 'Muse' is explicitly described as an autonomous AI agent capable of executing tasks on behalf of users, requiring broad permissions. The discovered Zero-Day vulnerability allows attackers to hijack these permissions and perform unauthorized actions, directly leading to harm such as breaches of user accounts and privacy violations. This fits the definition of an AI Incident because the AI system's malfunction (security flaw) has directly led to harm or the credible risk thereof. The event is not merely a potential hazard or complementary information; it reports a concrete security flaw with demonstrated exploitability, thus meeting the criteria for an AI Incident.[AI generated]
AI principles
Robustness & digital securityPrivacy & data governance

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

AI system task:
Interaction support/chatbots


Articles about this incident or hazard