🚨 SlowMist TI Alert: Muse Zero-Day 🚨
According to a disclosure by
@patrickwardle, a zero-day vulnerability in Muse for Mac could allow a local process without special privileges to hijack the AI assistant by modifying an undocumented setting.
⚠️ The flaw can redirect dictated prompts to an attacker-controlled endpoint, potentially enabling:
🎙️ Prompt/audio capture
💉 Prompt injection
🔑 Theft of authentication material
📱 Remote tasking of the user's connected mobile devices
Since Muse can access user-authorized data such as messages, emails, and financial information, a successful attack could potentially expose sensitive information accessible to the assistant.
🛡️ Users should avoid installing or running untrusted Muse-related PoCs and monitor for suspicious local activity until mitigations are available.
🔎 One of 0day PoCs:
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀
Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life.
But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.
Let me show you. 🧵
もっと見る