生成摘要机器翻译
PUB-8B3BB7237BMeta 修复 Muse macOS AI 智能体应用中的零日漏洞
安全研究员 Patrick Wardle 在 Meta 的 Muse macOS 应用程序中发现了一个零日漏洞,该漏洞允许本地代码劫持该 AI 智能体的未公开设置、重定向转录端点、访问用户账户、写入恶意文件并在不提醒用户的情况下拍照。Meta 随后发布了热修复补丁以修复该本地提权漏洞。
严重度观察36/100
证据置信度42%1 独立来源
证据状态信号已发布
发生了什么
安全研究员 Patrick Wardle 在 Meta 的 Muse macOS 应用程序中发现了一个零日漏洞,该漏洞允许本地代码劫持该 AI 智能体的未公开设置、重定向转录端点、访问用户账户、写入恶意文件并在不提醒用户的情况下拍照。Meta 随后发布了热修复补丁以修复该本地提权漏洞。
The vulnerability allowed significant unauthorized control over the AI agent and local device actions, but required existing local access on the victim's device and was quickly patched via a hotfix.
证据摘录
- A zero-day vulnerability was discovered in Meta's Muse macOS application by security researcher Patrick Wardle.
- The vulnerability allowed local attackers to redirect transcription processing and leverage Muse's agent privileges to write files and take pictures without alerting users.
- Meta issued a hotfix to patch the local privilege escalation vulnerability.
严重度维度
影响40
规模25
控制损失60
可利用性45
紧迫性30
不可逆性10
来源引用
- Meta patches Muse exploit that let attackers control the AI agentThe Verge Artificial Intelligence · 2026-09-22