Meta's adorable AI is, predictably, a security nightmare

The cutesy Muse avatar, Jolly, lulls users into a false sense of security as the AI gives their address out to Facebook users. 

Meta's adorable AI is, predictably, a security nightmare

Here’s some good advice you probably shouldn’t be getting from a pop-culture website: Stop giving Meta new opportunities to ruin your life. Mark Zuckerberg has proven himself time and again to be an untrustworthy individual with your data, and his company’s latest attempt to actually make something is turning out to be no different. All the reporting on Muse AI, Meta’s shiny new AI product, shows how, regardless of how many social media users long to have sex with Jolly, the adorable Muse mascot, Muse AI is not delivering on its promises to “make purchases, generate images, create documents, and connect with your favorite apps and services.” Sure, the phone calls it promises to make are made by humans, but shortly after its release, Mac security expert Patrick Wardle discovered, get this, a major security flaw. The zero-day vulnerability (meaning it was a problem with the system when it shipped) allows hackers to gain control of the Muse client and do pretty much whatever they want on the victim’s computer. 

“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica last week. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” 

“They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome.”

But wait, there’s more. Because Muse is connected to the world’s biggest social media ghost town, Facebook, and it was designed to speak with your friends, colleagues, and customers so you don’t have to, it can also send some personal information to them without your noticing. Per freelance reporter Karl Bode, Tech YouTuber Matt Robb had Muse run his Facebook Marketplace for the day, and in Robb’s words, “It told people my address and agreed [to] a lowball price, and then they showed up without it even telling me until late tonight that it messed up.” 

“Bad news on the MX Keys Mini pickup,” Muse reports. “Usman showed up at your building around 9:15 and waited, messaged a bunch of times, and nobody came down. He left angry at 9:38 and left a negative rating. Worse, my auto-reply told him ‘Yep I’m here!’ at 9:27 when you clearly weren’t available, which is on me. That’s a bad look and it made the no-show worse.”

Despite the many boneheaded things Muse AI is doing, Meta is currently preparing to sell it as a Tamagotchi-sized keychain so people can bring these problems everywhere. All the while, Meta is enjoying a nice surge in its stock price as its unfirable CEO continues to settle lawsuits from parents for addicting their children to Facebook and Instagram. Hey, we can’t say he didn’t warn us. This is what moving fast and breaking things looks like.

 
Join the discussion...
Keep scrolling for more great stories.