這宗雲端漏洞與另一宗 Mac app 漏洞不同;後者涉及已在電腦上運行的程式改道 Muse 聽寫流量,並可能取得驗證資料。
新漏洞的技術細節、是否需要使用者作出某種操作,以及底層問題是否已修補,目前都未有公開說明。
What vulnerability did a security researcher find in Meta’s Muse AI agent, how could malicious links or unprivileged local apps potentiallyIllustrative image; it does not depict Muse’s actual interface or either reported vulnerability.
AI 提示
Create a landscape editorial hero image for this Studio Global article: What vulnerability did a security researcher find in Meta’s Muse AI agent, how could malicious links or unprivileged local apps potentially. Article summary: An outside researcher reported a Muse vulnerability that could potentially let an attacker reach a user’s sensitive information. Meta is adding a clearer in-app safety warning, but the available reporting does not establ. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts wi
openai.com
Meta 的 Muse AI 代理據報發現一項安全漏洞,攻擊者可能藉此接觸使用者的專屬雲端環境,當中或有電郵和檔案。Meta 正在 Muse 內加入更清晰的安全提示;不過,公開報道沒有交代漏洞的技術細節,也未說明使用者需要做甚麼才可能觸發攻擊。118
要留意,這宗雲端漏洞,與之前披露的 Muse Mac app 漏洞是兩回事。資安研究員 Patrick Wardle 指出,若有程式已在 Mac 上運行,便可能改動 Muse 的聽寫設定,令語音輸入流量改送到別處,並可能暴露驗證資料。兩宗事件的攻擊方式不同,不應混為一談。71013
新報告指雲端環境或有被接觸風險
據路透社引述《The Information》報道,一名外部研究員透過 Meta 的漏洞懸賞計劃通報問題。根據報道,漏洞可能讓攻擊者接觸使用者的專屬虛擬機——即與個別使用者相關的雲端環境,當中可能存有電郵和檔案。118
目前公開資料沒有交代攻擊者會如何利用這個漏洞。報道亦未證實惡意連結是否攻擊途徑、使用者是否需要點擊或批准任何操作,或通訊內容及進行中的登入工作階段是否受到影響。因此,不能把另一宗 Mac 漏洞的細節當成這宗雲端漏洞的攻擊方式。