Meta's adorable AI is, predictably, a security nightmare
The cutesy Muse avatar, Jolly, lulls users into a false sense of security as the AI gives their address out to Facebook users.
Credit: Alexandr Wang via X
Here’s some good advice you probably shouldn’t be getting from a pop-culture website: Stop giving Meta new opportunities to ruin your life. Mark Zuckerberg has proven himself time and again to be an untrustworthy individual with your data, and his company’s latest attempt to actually make something is turning out to be no different. All the reporting on Muse AI, Meta’s shiny new AI product, shows how, regardless of how many social media users long to have sex with Jolly, the adorable Muse mascot, Muse AI is not delivering on its promises to “make purchases, generate images, create documents, and connect with your favorite apps and services.” Sure, the phone calls it promises to make are made by humans, but shortly after its release, Mac security expert Patrick Wardle discovered, get this, a major security flaw. The zero-day vulnerability (meaning it was a problem with the system when it shipped) allows hackers to gain control of the Muse client and do pretty much whatever they want on the victim’s computer.
“We can manipulate the agent and leverage its privileges to do whatever we want,” Wardle told Ars Technica last week. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.”