Meta Platforms' AI product, Muse, has been reported to have security vulnerabilities that could compromise user data and virtual environment security, prompting Meta to plan enhanced risk warnings. The vulnerabilities were reported by external security researchers through Meta's bug bounty program and had not been publicly disclosed before. These vulnerabilities could allow attackers to access users' exclusive virtual machines and obtain personal data stored in the cloud, such as emails and documents. A Meta spokesperson stated that the vulnerabilities were initially classified internally as SEV-2, the second-highest level in a five-tier security classification, but were later adjusted to SEV-3. Meta indicated that an attack exploiting these vulnerabilities would require a prerequisite condition: the user must either summarize information in Muse or click on a malicious link, and then click 'Allow' to authorize in the security pop-up window. To address this, Meta will introduce more prominent warning prompts. If Muse detects that a user is about to visit a malicious website, it will display an enhanced warning as an additional layer of protection.
