Patrick Wardle on X: "Yes, I noted this attack was local, but there’s also a remote vector: ClickFix ☠️
A single user-run command could hijack Muse, then give a *remote* attacker (Muse-scoped) control over all of the victim’s Muse-enabled devices, including iOS 👀
https://t.co/QBszVNCL0V"
Yes, I noted this attack was local, but there’s also a remote vector: ClickFix ☠️
A single user-run command could hijack Muse, then give a *remote* attacker (Muse-scoped) control over all of the victim’s Muse-enabled devices, including iOS 👀
Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀
Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life.
But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.
Let me show you. 🧵
First, one of 0day PoCs: github.com/pwardle/not-a-…
Run with `-h` for some fun options from the 50+ commands Muse exposes.
Then click Muse’s 🎙️ and dictate a prompt. That’s the trigger. 👀
#3 (This) bug details
Muse has an undocumented setting:
endo_voyager_dictation_endpoint
...that can be redirected locally with no special privileges!
So when you click 🎙️ and dictate a prompt, Muse sends it to the attacker’s endpoint instead 🤦♂️
#4 Why is this bad?
On a scale of meh to f*cked:
🎙️ Steal your dictated audio
💉 Inject prompts Muse trusts/executes
🔑 Steal your auth token & invisibly control Muse directly
Anything you gave Muse access to? Now the (local) attacker has it too: msgs, emails, finances... 💀
Stay safe out there! And if you’re into this kind of bug, or building/defending AI agents, I’ll share more details (and more bugs) at #OBTS v9:
objectivebythesea.org/v9/index.html
Would be stoked if you could join!
Yes, I noted this attack was local, but there’s also a remote vector: ClickFix ☠️
A single user-run command could hijack Muse, then give a *remote* attacker (Muse-scoped) control over all of the victim’s Muse-enabled devices, including iOS 👀
Personally, I’m a fan of full disclosure 😇
It gets bugs fixed faster, and well the last time I dealt indirectly with Facebook’s bug bounty program, its security chief mentioned involving law enforcement over my colleague’s research 😬
@Meta has now patched this @Muse bug. Thanks for the quick fix! 🤩
And speaking of thanks, I’d be remiss not to thank my Muse @andyrozen ...especially since poking on @Muse was her idea in the first place! 💡🤓☝️💭🤔