ME News message, September 22 (UTC+8). Promptly reports: Beating AI. Meta's personal AI Agent Muse has just launched for two weeks, and security researcher Patrick Wardle has already identified a local zero-day vulnerability. If an attacker can get a piece of code to run on a Mac under the current user's identity, they can modify a hidden setting in Muse to reroute voice requests to the attacker's server. The code does not require any additional macOS permissions. After that, it could intercept the content the user speaks to Muse, inject malicious instructions, and possibly obtain Muse's authentication credentials. Muse itself can access system resources such as files and the camera. Whatever permissions the user grants to Muse, a malicious program may leverage Muse to invoke those permissions. However, this is not a vulnerability that enables remote “in-the-air” intrusion of a Mac—an attacker must first get the code to run locally. When Meta launched Muse, it specifically emphasized secure design and also added a Muse Secure VM and a separate Sentinel Agent. Unexpectedly, the first zero-day vulnerability turns out to be a hidden setting that can be modified by a standard local process on the Mac client. (Source: ME)