Beware: Meta's agent can take over your camera without warning

A cybersecurity researcher has uncovered a severe security vulnerability in Meta's Muse AI agent for macOS, allowing local malicious commands to hijack the computer and activate the camera without any user notification. Meanwhile, Amazon has blocked Muse's access to its services over privacy concerns. The launch has surpassed 2.5 million downloads.

Cybersecurity researcher Patrick Wardle has revealed a critical zero-day vulnerability in the desktop version of Meta's Muse AI agent for macOS. The flaw allows a local malicious command to change the transcription data's target server, steal the user's account access token, and exploit the extensive permissions already granted to the agent to take over the computer, write files to the system, and even take photos and record through the microphone without any indication or alert to the user. Meanwhile, Amazon has announced it has completely blocked Muse's access to its services, citing serious privacy concerns and unauthorized scanning activity that violates its terms of service. Muse, based on the Muse Spark 1.3 model, has recorded one of the fastest launches in the tech industry, surpassing 2.5 million downloads and overtaking ChatGPT in App Store charts. Meta's stock has surged about 25% this month alongside the launch of premium tiers costing up to $100, but the security flaw and site blocks cast doubt on the project's future.

Beware: Meta's agent can take over your camera without warning