
Xadgudub casri ah oo ku jira barnaamijka AI ee Meta: Muse wuxuu u ogolaanayaa in la xakameeyo
Shirkadda Meta ayaa soo saartay barnaamijka AI-ka ah ee Muse, kaas oo u ogolaanaya macaamiisha inay sameeyaan shaqooyin kala duwan, laakiin xadgudub casri ah oo aan la ogeyn ayaa laga helay, kaas oo u ogolaanaya in kooxaha weerarayaasha ay helaan nidaamka macaamiisha.
Muse: Barnaamijka AI-ka ah ee Meta
Shirkadda Meta ayaa muddo bil ah ka hor soo saartay barnaamijka AI-ka ah ee Muse, kaas oo u ogolaanaya macaamiisha inay sameeyaan shaqooyin kala duwan sida qorista codsiyada, diiwaangelinta, iyo adeegga macaamiisha. Barnaamijkan wuxuu sidoo kale u ogolaanayaa inuu sameeyo iibsiga, sameynta sawirrada, iyo sameynta warbixinnada.
Barnaamijkan wuxuu u shaqeeyaa macOS, laakiin ma jiro nidaam Windows. Wuxuu sidoo kale u ogolaanayaa inuu la shaqeeyo WhatsApp, email, iyo barnaamijyada kale ee shakhsiyeed. Marka barnaamijka uu u baahan yahay adeeg aan jirin, wuxuu sameeyaa mid cusub si uu u fuliyo shaqada loo dhiibay.
Xadgudubka casriga ah ee Muse
Xadgudub casri ah oo aan la ogeyn ayaa laga helay Muse, kaas oo u ogolaanaya in kooxaha barnaamijyada iyo amarrada terminal-ka ay helaan nidaamka macaamiisha. Xadgudubkan wuxuu u ogolaanayaa in kooxaha weerarayaasha ay beddelaan goobta codsiga, taas oo u ogolaanaysa inay helaan nidaamka macaamiisha.
Marka barnaamijka uu beddelo goobta codsiga, wuxuu u ogolaanayaa in kooxaha weerarayaasha ay helaan nidaamka macaamiisha. Xadgudubkan wuxuu sidoo kale u ogolaanayaa in kooxaha barnaamijyada ay beddelaan goobta codsiga, taas oo u ogolaanaysa inay helaan nidaamka macaamiisha.
Jawabta Meta iyo Amazon
Mark Zuckerberg, hoggaamiyaha Meta, wuxuu sheegay in Muse uu u ogolaanayo inuu sameeyo shaqooyin kala duwan, laakiin xadgudubkan casriga ah wuxuu muujiyay in barnaamijkan uu u ogolaanayo in kooxaha weerarayaasha ay helaan nidaamka macaamiisha. Xadgudubkan wuxuu sidoo kale u ogolaanayaa in kooxaha barnaamijyada ay beddelaan goobta codsiga, taas oo u ogolaanaysa inay helaan nidaamka macaamiisha.
Amazon ayaa maanta bilaabatay inay ka joojiso barnaamijka Muse, taas oo muujinaysa in shirkaddan ay ka xumahay xadgudubkan casriga ah. Xadgudubkan wuxuu sidoo kale u ogolaanayaa in kooxaha barnaamijyada ay beddelaan goobta codsiga, taas oo u ogolaanaysa inay helaan nidaamka macaamiisha.
Meta's new AI assistant Muse, which can book appointments, fill out forms, and connect to WhatsApp and email, has been found to contain a serious zero-day vulnerability that grants locally run apps and terminal commands complete control over the agent.
A Powerful Assistant with Privileged Access
Meta introduced Muse a few weeks ago as a highly capable AI assistant that can proactively take tasks off users' plates and connect with their favorite apps and services. The macOS app works with WhatsApp, email, calendar, and social media accounts, though no Windows version exists. To use these features, users must first grant Muse access to their accounts and broad device resources such as the microphone, camera, and location data.
Meta founder and CEO Mark Zuckerberg has claimed Muse is built from the ground up for privacy and security. However, the assistant completely undoes Apple's default security measures designed to prevent installed apps or terminal commands from accessing restricted device resources. This includes the ability to write files to disk, access the mic and camera, and monitor location and calendars.
The Zero-Day Flaw Exposes User Accounts
The zero-day vulnerability allows any locally installed app or executed code to change a long list of undocumented settings within Muse, regardless of the macOS permissions it holds. Most of these settings are innocuous, such as controlling dark mode, but one setting is particularly dangerous. It allows processes to change the endpoint where transcription occurs, normally a server address operated by Meta.
Attackers can exploit this flaw by redirecting the transcription endpoint to their own server, thereby gaining the authentication token that gives complete control over the Muse account. This means any app or terminal command can access the token that authenticates users to their Muse account, effectively compromising their entire setup.
Amazon Blocks Muse Amid Growing Concerns
Amazon began blocking Muse from its site on Sunday, further raising questions about the assistant's security posture. The zero-day vulnerability has prompted serious doubts about the safety of the platform, despite Meta's assurances about its security architecture.
The incident highlights the risks associated with granting AI assistants extensive access to device resources and user accounts. As Muse continues to evolve, the need for robust security measures becomes increasingly critical to protect user data and privacy.
Ilaha iyo xuquuqda sawirka
Sawir: Ars Technica Xigasho



