People are giving Meta access to their emails, messages and calendars and other apps? Are they out of their mind or what am I missing?
Who in their right mind would install a Meta AI with near admin privileges?
> macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device
Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…
Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
How is this a serious zero day if it requires local code execution to run?
Is 12 hours to deliver a local privilege escalation fix not a good response time?
I love that when you open a web inspection console on facebook, it says "Stop! This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or "hack" someone's account, it's a scam and will give them access to your Facebook account. See https://www.facebook.com/selfxss for more information."
I'm confused what the vulnerability is. Does macOS have some specific function for protecting key material, that it's unexpected that if you execute user-privileged code locally, outside of a sandbox, it gets full read access?
A zero day? Of course it does. It likely has many. Given the history of software, it's impossible to think it wouldn't.
The "zero day" is something they call a "ClickFix Attack"
Upon Googling "ClickFix":
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.