A recently discovered vulnerability in Meta’s Muse AI assistant for Mac could allow existing malware to exploit the assistant as a backdoor, according to a proof-of-concept revealed by security researcher Patrick Wardle on September 21. This issue arises from a hidden setting that can redirect user dictations to an attacker rather than Meta.
Understanding the Security Flaw
The flaw affects the Mac version of Muse and requires the attacker to have the ability to run code as the logged-in user. This vulnerability does not provide a means of remotely accessing a Mac computer. Muse, launched by Meta in the U.S. earlier this month, integrates with various personal apps and services based on the permissions granted by the user.
Wardle highlights the risk associated with the broad access Muse has. He advises users against installing the assistant, noting the simplicity with which it can be manipulated into a backdoor. Despite macOS’s security measures, which typically prevent app interference, Muse’s permissions could be exploited to access sensitive user information.
Potential Threats and Implications
The setting in question, named endo_voyager_dictation_endpoint, is located within the app’s preferences. It can be altered by any program operating under the user’s account, allowing dictation data to be rerouted to a malicious program instead of Meta.
Wardle demonstrated several potential exploits, including intercepting what users dictate, injecting additional instructions that Muse would execute, and seizing control of the Muse session through its token. This vulnerability extends beyond Macs, enabling an attacker to manipulate the Muse app on other devices like iPhones, although certain actions, like sending messages, remain restricted.
Protective Measures for Users
As there is no immediate fix available, users are urged to take precautionary steps. Disabling or removing Muse until a patch is released is recommended to mitigate risk. Reviewing and restricting Muse’s app permissions can also reduce exposure to potential threats. In cases where a Mac has been compromised, users should treat linked accounts as vulnerable and update passwords accordingly.
Meta emphasizes Muse’s security, claiming their cloud infrastructure is designed to isolate user data and ensure secure operations. However, this flaw in the Mac app bypasses those cloud protections, raising concerns about Meta’s approach to handling dictation outside of Apple’s built-in systems.
Looking Forward
The discovery of this vulnerability underscores the importance of vigilant cybersecurity practices, especially as AI assistants become more integrated into daily life. Users are encouraged to stay informed about updates and potential patches from Meta to ensure their data remains secure.
