外部研究員透過 Meta 漏洞獎勵計劃通報 Muse 漏洞;問題可能讓攻擊者進入用戶的專屬虛擬機,接觸當中的電郵和檔案。
Meta 據報正為 Muse 加入更清晰的安全提示,但現有報道未交代漏洞的具體技術機制,也未證實有人曾利用漏洞取得資料。
What vulnerability did an outside researcher report through Meta’s bug bounty program in its recently launched Muse AI agent, what sensitiveIllustration of the privacy risks raised by a reported vulnerability in Meta’s Muse AI agent.
AI 提示
Create a landscape editorial hero image for this Studio Global article: What vulnerability did an outside researcher report through Meta’s bug bounty program in its recently launched Muse AI agent, what sensitive. Article summary: An outside researcher reported a Muse flaw through Meta’s bug bounty program that could have allowed an attacker to access a user’s sensitive information. Meta’s reported response was to make Muse’s safety warning cleare. Topic tags: general, news, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
openai.com
Meta 的 AI 代理 Muse 被揭發存在安全漏洞。一名外部研究員透過 Meta 的漏洞獎勵計劃通報問題;據報,漏洞可能讓攻擊者存取用戶的專屬虛擬機,當中可能存有電郵和檔案。現有報道描述的是潛在風險,並無證據證實有人曾藉此存取或盜取用戶資料。111
漏洞可能涉及甚麼資料?
Muse 會為用戶提供專屬虛擬機(VM),即個別的雲端運算環境。根據《The Information》查閱的 Meta 內部事件報告,這項漏洞可能讓攻擊者進入用戶的虛擬機,接觸儲存在其中的資料,包括電郵和檔案。12