Account hijacking flaw found in Meta’s Muse for macOS; hotfix releasedMachine translation
Security researcher Patrick Wardle found that an undisclosed Muse voice configuration setting could be changed by an app or script running with the user’s permissions. An attacker could use it to intercept voice commands and an authentication token, then control the signed-in account and its connected apps. Meta says it has removed the setting in a hotfix.
漏洞将可修改的语音配置项与账户认证 Token 联系起来,影响可能延伸至 Muse 已获授权的关联应用。
Account hijacking flaw found in Meta’s Muse for macOS; hotfix released
Security researcher Patrick Wardle found that an undisclosed Muse voice configuration setting could be changed by an app or script running with the user’s permissions. An attacker could use it to intercept voice commands and an authentication token, then control the signed-in account and its connected apps. Meta says it has removed the setting in a hotfix.
漏洞将可修改的语音配置项与账户认证 Token 联系起来,影响可能延伸至 Muse 已获授权的关联应用。
材料 ce899330920d48eb9b61704c92ded769;建议 a4264bfbfe784dab82c13d52c4745e69;系统证据核验通过,非人工审稿。
Read at the original source