The zero-day exploit required local access to the user’s device, but gave potential attackers access to Muse accounts. | Image: The Verge Meta has issued a patch for its Muse macOS app following the discovery of a zero-day vulnerability that could allow someone to take control of the AI agent. The bug found by security researcher Patrick Wardle utilized an undocumented Muse setting that enabled potential attackers running local code to redirect transcription processing from Meta's servers to their own endpoint, Ars Technica reports, giving the attacker access to the Muse account. Several design decisions reportedly enabled this flaw, including having Muse dictation occur in the cloud instead of on-device, and allowing any app to control all of Muse's undocumented settings. Pr … Read the full story at The Verge. from The Verge https://ift.tt/RgzylH5
In 2021, as a whistleblower emerged with dramatic allegations that Facebook was harming children, CEO Mark Zuckerberg posted a rebuttal on Facebook . “We care deeply about issues like safety, well-being and mental health. It’s difficult to see coverage that misrepresents our work and our motives,” he wrote in a note to Meta staff, which he reposted publicly. “At the most basic level, I think most of us just don’t recognize the false picture of the company that is being painted.” Away from the stream of often inane public replies, one reader didn’t like what they saw. Zuckerberg spoke with the unidentified person privately on WhatsApp , according to exhibits later released as part of a series of lawsuits, and the figure urged Zuckerberg — a parent himself — to make child safety even more central in his messaging. “i am not saying facebook is duplicitous and evil,” they wrote. “i am saying the opposite, you have heard the chorus and will PERS...