
The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta
Meta has patched a security vulnerability in its Muse macOS app that allowed attackers with local access to a user's device to take control of the AI agent and access the user's account. The exploit worked by redirecting the app's cloud-based transcription processing to an attacker's own server, and attackers could use the compromised agent to take pictures and write files to disk. The vulnerability existed because of several design choices, including performing dictation in the cloud rather than on-device and allowing any app to control undocumented Muse settings. While Meta stated the real-world risk was minimal since the exploit required local device access, a security researcher noted that the company should have prioritized security from the beginning of development.

As the US and China race to become the dominant power in the AI industry, the countries also appear to be figuring out ways to communicate on national security issues.

OpenAI CEO Sam Altman discusses AI safety, human control, and international cooperation in remarks to the United Nations Security Council.

Paolo Benanti tells WIRED that hysteria over whether godlike AI could destroy humanity is distracting from the need for public debate about how to govern the technology.
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven