What was the zero-day vulnerability Patrick Wardle found in the Mac version of Meta’s Muse AI assistant, how could malware already running oIllustration of the security risks surrounding Muse for Mac’s dictation feature; not an image of Wardle’s demonstration.
AI 提示詞
Create a landscape editorial hero image for this Studio Global article: What was the zero-day vulnerability Patrick Wardle found in the Mac version of Meta’s Muse AI assistant, how could malware already running o. Article summary: Patrick Wardle found a local privilege-boundary flaw in Muse for Mac: an ordinary process could change an undocumented dictation setting and redirect traffic meant for Meta to an attacker-controlled server. His proof of . Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
openai.com
Meta 的 Mac 版 AI 助理 Muse,出問題的不是語音辨識本身,而是語音要送去哪裡辨識。安全研究員 Patrick Wardle 發現,Mac 上已在執行的程式可改寫 Muse 一項未公開的設定,把聽寫內容從 Meta 的伺服器導向攻擊者控制的伺服器;對方還可能取得用來驗證 Muse 帳號的權杖。Wardle 為此製作了名為 not-a-mused 的概念驗證程式。這項漏洞不能單獨讓攻擊者從遠端入侵 Mac。811
從聽寫設定到帳號風險
關鍵設定名為 endo_voyager_dictation_endpoint,決定 Muse 將聽寫提示詞送往哪個端點進行轉錄。Wardle 發現,在 Mac 本機執行的應用程式或「終端機」指令,不需取得特殊 macOS 權限就能修改它。若端點遭改指向攻擊者的伺服器,使用者下一次以語音輸入時,聽寫流量便可能送到錯誤目的地,暴露語音內容及驗證資料。7828
攻擊因此有兩個重要前提:程式必須已能在使用者的 Mac 上執行,而且使用者要啟用聽寫。這不是只要使用 Muse,所有對話就會自動遭到攔截的漏洞;真正值得留意的是,一個本身沒有特殊權限的本機程式,可能藉此取得權限更廣的助理帳號存取能力。7828