返回全部动态

Meta Muse 客户端被曝零日漏洞:调试配置可绕过 macOS 安全边界

原标题:Un-Mused: How a Single Debug Setting Bypassed macOS Security in Meta’s AI Client

InfoQ AI ML and Data Engineering安全质量 75

AI 摘要

安全研究员 Patrick Wardle 披露 Meta 新推出的 macOS 版 Muse AI 助手存在未修补的零日漏洞,攻击者可利用未公开的调试配置项 endo_voyager_dictation_endpoint 将语音听写流量重定向至自有服务器,窃取音频与账户认证令牌,并借代理注入实施提示注入攻击。Meta 将该问题定性为内部配置缺陷,未申请 CVE,仅通过热修复从生产版本中移除该调试配置项。此事紧随亚马逊以违反自动化代理访问政策为由封禁 Muse 之后发生。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

Security researcher Patrick Wardle, founder of the Objective-See Foundation, has disclosed an unpatched zero-day vulnerability affecting Meta's newly released desktop client for Muse on macOS. While Meta Chief Executive Officer Mark Zuckerberg had claimed that the autonomous artificial intelligence assistant was built from the ground up for privacy and security, the reported flaw enables locally running software or shell commands to hijack the application. Through this vector, unprivileged softw


发布时间:2026-09-24 22:14
抓取时间:2026-09-24 23:04
来源机构:InfoQ
阅读原文infoq.com