Meta hotfixes Muse Mac flaw after researcher’s disclosure
Meta issued a hotfix for its Muse Mac app after security researcher Patrick Wardle disclosed a flaw that could let code already running on a user’s computer redirect the assistant’s dictation traffic and capture its authentication token. The vulnerability could allow an attacker to use Muse’s existing account permissions, though Meta said the practical risk was low because the attack required a local foothold. The flaw involved an undocumented setting in the app’s local preferences that controlled which server received audio for transcription. Wardle’s proof of concept, published September 21, showed that another program running under the same user account could change the setting and send dictation traffic to an attacker-controlled server. The captured data could include audio and a Muse authentication token. With that token, malicious code could act through Muse using permissions the user had granted the assistant, rather than obtaining each permission separately.