logoalt Hacker News

Meta’s Muse has a serious 0-day

92 pointsby pavel_lishintoday at 2:35 PM37 commentsview on HN

Comments

gavinraytoday at 4:30 PM

The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
show 2 replies
tw600040today at 6:36 PM

People are giving Meta access to their emails, messages and calendars and other apps? Are they out of their mind or what am I missing?

willtemperleytoday at 3:06 PM

Who in their right mind would install a Meta AI with near admin privileges?

show 8 replies
yaloktoday at 3:42 PM

> macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

sippingabonedrytoday at 3:39 PM

Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.

show 2 replies
iltoday at 4:19 PM

How is this a serious zero day if it requires local code execution to run?

adamsb6today at 4:46 PM

Is 12 hours to deliver a local privilege escalation fix not a good response time?

chewstoday at 5:37 PM

I love that when you open a web inspection console on facebook, it says "Stop! This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or "hack" someone's account, it's a scam and will give them access to your Facebook account. See https://www.facebook.com/selfxss for more information."

show 1 reply
peri-cltoday at 3:19 PM

I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?

show 1 reply
SoftTalkertoday at 3:31 PM

A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.

show 1 reply