๐จ SlowMist TI Alert: Muse Zero-Day ๐จ
According to a disclosure by
@patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting.
โ ๏ธ The flaw can redirect dictated prompts to an attacker-controlled endpoint, potentially enabling:
๐๏ธ Prompt/audio capture
๐ Prompt injection
๐ Theft of authentication material
๐ฑ Remote tasking of the user's connected mobile devices
Since Muse can access user-authorized data such as messages, emails, and financial information, a successful attack could potentially expose sensitive information accessible to the assistant.
๐ก๏ธ Users should avoid installing or running untrusted Muse-related PoCs and monitor for suspicious local activity until mitigations are available.
๐ One of 0day PoCs:
Please don't install - it's trivial to turn Muse into the ultimate backdoor ๐๐
Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life.
But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.
Let me show you. ๐งต
Show more