Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.”
Further raising questions, Amazon on Sunday began blocking Muse from its site.
When a task needs a tool that doesn’t exist, Muse creates one on the fly.
The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account.
About 12 hours before Wardle disclosed the zero-day, Amazon started blocking people from using Muse to shop on the site.
5 sentences from our version of the report,
chosen to cover it. Nothing here is written; every line is in the article below.
How
Summarized version
For Muse to do any of these things, users must first give it access to their accounts.
Headline check
Headline as published: Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
All two things this headline claims are in the report.
Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. How this is checked
The article, shortened and in plain language
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site.
Meta introduced Muse a few weeks ago. The macOS app also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task needs a tool that doesn’t exist, Muse creates one on the fly.
Of course, for Muse to do any of these things, users must first give it access to their accounts.
The zero-day allows any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings.
“We can manipulate the agent and leverage its privileges to do whatever we want,” Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars.
One is the choice for Muse dictation to occur in the cloud, where Meta can log it. macOS has long provided a means for apps to handle dictation and transcription in processes that stay securely on the device.
About 12 hours before Wardle disclosed the zero-day, Amazon started blocking people from using Muse to shop on the site.
Shortened to 1 minute
of reading, this version reads 9 on the Niral Score.
You are reading our version, not theirs.
This is Ars Technica's report shortened to its most important sentences, in plainer words, with
verdicts and loaded words taken out. Plain description stays, and so do adjectives
that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations
are theirs — quotations are never edited — and the indicators beside it measure
this version. Hover or tap Adjectives to see every one left in the text.
How this outlet filed it, and how we rewrote it
No other newsroom we read has filed on this event, so there is nothing to compare it with yet.
Readers can ask a question about this story here.
Questions and answers are for subscribers.
Sign in
to read them.
Comments are read before they appear where anything in them needs a person to look.
Nothing posted here is ever deleted; a comment taken down keeps its text and the reason,
so the decision can be looked at again. How this works