InfoQ 中文T2·68 pts
Meta Muse macOS Client Zero-Day Bypasses Permissions via Config Key
Original: 苹果筑起的权限高墙,被 Meta AI 助手“借道”绕过
- Non-privileged local processes can silently overwrite critical Muse client configuration keys, hijacking traffic without triggering macOS authorization prompts.
- Attackers can simultaneously steal raw microphone audio and valid authentication tokens, enabling undetected man-in-the-middle attacks.
- With session credentials, attackers can use prompt injection to drive the AI assistant to perform malicious background tasks like file exfiltration.