Meta's newly released AI assistant, Muse, has been found to harbor a critical zero-day security vulnerability. This flaw enables local applications or terminal commands to acquire authentication tokens for a user's Muse account, granting them complete control over the account. Considering that the macOS iteration of Muse operates with elevated system privileges, malicious actors could leverage this to execute high-risk actions, including the creation of harmful files, capturing photos, accessing user data, and beyond. Presently, Amazon has initiated measures to block Muse on its platform, amplifying concerns from external observers.
