Meta adds safety warning to Muse after security flaw, The Information reports
A researcher found a vulnerability that could let an attacker access a user's sensitive personal information, including emails and files, according to The Information.
(Adds details from report and background) Sept 25 (Reuters) — Meta Platforms is adding a clearer safety warning within Muse after a security researcher discovered a vulnerability in the AI agent that could let an attacker access a user's sensitive personal information, the Information reported on Friday. The flaw, reported by an outside researcher through Meta's bug bounty program and not previously disclosed, could have allowed an attacker to access a user's dedicated virtual machine — an individualized cloud-based account containing data including emails and files, according to an internal Meta incident report reviewed by The Information.
The vulnerability was initially classified as a "SEV-2," Meta's third-highest severity level on a five-point scale, typically used for incidents with significant impact, the report said. Meta did not immediately respond to a Reuters request for comment. Muse, launched earlier this month, is Meta's personal AI agent designed to carry out tasks such as shopping, travel booking, emailing and payments on behalf of users. 8 million downloads in its first two weeks.
com;)