Meta patches Muse security flaw as AI agent expands into business tools
publishers 27articles 45first reported 23 Sep, 14:37 UTCdeveloping since 22 Sep · 9 editions
Meta issued a hotfix for its Muse macOS app after security researcher Patrick Wardle identified a vulnerability that could let malicious software already running on a user’s computer redirect the agent’s cloud-based transcription processing to an attacker-controlled server.
According to The Verge, Wardle’s proof-of-concept attacks used Muse’s privileges to take photographs and write malicious files to disk, sometimes without alerting the user. Meta said the flaw was a local privilege-escalation issue rather than a remote exploit and therefore required malicious code to already be running under the user’s account. The company patched it within hours of Ars Technica publishing its report.
The fix comes as Meta broadens Muse beyond its newly launched consumer assistant. The company announced Meta Enterprise Platform, which will offer businesses and developers products including Muse, Meta Business Agent, Muse API and Muse Code. Meta hired MongoDB CEO Chirantan “CJ” Desai to lead the initiative; MongoDB named former CEO Dev Ittycheria interim chief executive while it searches for a permanent replacement.
Meta also introduced Muse for Small Business, allowing users to connect Facebook and Instagram professional accounts, advertising data and third-party services including Slack, Shopify, QuickBooks, Canva and Zoom. Meta says the agent can analyze business performance and carry out tasks such as managing advertising campaigns.
Muse has rapidly climbed app-download rankings, while OpenAI has introduced a competing always-on agent called Dots for ChatGPT Pro subscribers. OpenAI says Dots can use connected apps to complete multistep tasks and request approval before sensitive actions.
HOW THIS STORY WAS MADE
Written from 8 articles, 6 with the publisher's own text; 8 independent newsrooms once syndicated copies count as one; this version written 17 h after the record first saw the story; the editor kept it as written.
- Publishers
- 27
- Source articles
- 45
- Given to the writer
- 8, 6 with the article's own text
- Independent newsrooms
- 8
- This version written
- 17 h after the record first saw the story
- Second model (editor)
- kept as written
- Publication gate
- passed
- Human review
- none
Written by a language model from the sources above, then checked by a second model that may only cut, attribute or correct. How it works →