One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Summary

A security researcher has demonstrated a proof-of-concept that allows malware on a Mac to hijack Meta's Muse AI assistant. This exploit works by altering a hidden setting, redirecting the user's dictated prompts to an attacker instead of the intended AI service.

IFF Assessment

FOE

This finding reveals a new attack vector that allows malicious actors to exploit legitimate AI tools for unauthorized data exfiltration, posing a direct threat to user privacy and system security.

Severity

7.5 High (AI Estimated)

This vulnerability has a significant impact as it allows for sensitive data interception (confidentiality) and can be exploited remotely without user interaction beyond the initial malware infection, leading to an elevated attack vector and exploitability.

Defender Context

This highlights the importance of scrutinizing permissions granted to AI applications, especially those requiring broad system access like microphone input. Defenders should be aware of how malware can subvert even seemingly benign applications to act as backdoors for data theft and lateral movement.

Read Full Story →