Meta fixes a bug in its AI for Mac that allowed it to take control of the assistant and access your WhatsApp conversations

Meta has fixed the bug Muse for Mac with a urgent patchpublished hours after the information from Ars Technica revealing it this morning, according to The Verge. The artificial intelligence assistant Muse of Goal It could become a tool to steal information from the user themselves. The security expert macOS Patrick Wardle discovered a bug that allowed them to control their account and take advantage of the permissions granted to the program on the computers of Apple. It was a zero day vulnerabilityfor which there was no correction when it became public.

Muse was presented a few weeks ago as an assistant capable of make purchases, book appointments and manage tasks on WhatsApp or email. To do this you need to access the user’s accounts. Your app for Mac also requires permissions to use computer resources, such as the camera, microphone, or files.

The problem was that any local application or terminal command could modify internal Muse settings even if he lacked the assistant’s permissions. One of them was the address of the server that transcribes the voice. If it was replaced with that of an attacker, Muse sent its authentication token there when the user dictated a command.

This token is a digital credential that identifies the user to the service without asking for their password in each operation and stealing it allows you to act on your behalf. The attacker’s server could also enter instructions for Muse to send a file with the WhatsApp messages to which it had access.

‘We can manipulate the agent and take advantage of his privileges to do whatever we want. So, Instead of having to write a very complete malicious program to steal information on a Mac, we can use the AI ​​assistant itself‘Wardle explained to the media.

Wardle criticized that the dictation was processed in the cloud when macOS allows it to be done within the device. According to the researcher, this alternative would have prevented the attack. He also questioned whether any application could modify such sensitive settings. Their tests allowed writing malicious files and taking photos without the user noticing anything in many cases.

‘For me, the level of security requirements of these applications is infinitely higher. They don’t have to be perfect, but when you look at Muse it seems like they didn’t think about security in my opinion, and that’s really worrying. At the very least, they should take it into account from the beginning, and simply they are not doing it‘ said Wardle.

To take advantage of the failure it was necessary run code on macsomething that could be achieved through a deception called ClickFix. A website simulates an error or verification and asks the user to copy and execute a command in the terminal, a supposed solution that launches the attack. Wardle found that a variant of this deception allowed him to take control of Muse.

David Singletonof Meta Superintelligence Labshas defended that the risk was low because the attack required malicious code previously running on the computer. The bug allowed the access of that code to be expanded by taking advantage of Muse permissions. Zuckerberg had promoted the assistant as ‘designed from the ground up to protect privacy and security’.

Some twelve hours before Wardle released the ruling yesterday, amazon started blocking purchases through Muse. Amazon considers that Muse breaches its terms of use and has asked Meta to stop allowing the assistant to make purchases on its platform. The company maintains that these applications must respect the merchants’ decision on whether to allow them to operate on their platforms.