A simple ClickFix attack is only one way to completely hijack the new agent.

122 points•pavel_lishin•8 days ago•49 comments•

49 comments

gavinray8 days ago
The "zero day" is something they call a "ClickFix Attack"

Upon Googling "ClickFix":

  > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
bachittle8 days ago
The exploit is a local zero day exploit, meaning the machine needs to already be compromised. For it to be a remote zero day exploit you need to do the ClickFix attack. The idea is that it lets you access much more machines and resources if the one machine with Muse is compromised. More info here: https://x.com/dps/status/2102248329111634067
failbuffer8 days ago
We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.
dspillett8 days ago
> > It typically compromises devices by manipulating victims into copying and pasting malicious commands

> […] that's idiocy that's as old as time.

And constantly being reinvented: `curl -sL some.unverified.stuff.sh | bash`

bigfishrunning8 days ago
Reminds me of playing Runescape back in the late 90s, you could double your money by just pressing alt-F4
analog318 days ago
Well if nothing else, idiocy that's as old as time started on day zero.
willtemperley8 days ago
Who in their right mind would install a Meta AI with near admin privileges?
josefresco8 days ago
"Normies" aka the average user on Meta. They have no concept of what "admin privileges" means and don't really care. I still have a hard time convincing my clients to use secure passwords. I have clients who were phished for substantial amounts of money and STILL don't implement proper security measures.
sandeepkd8 days ago
Almost everyone who is struggling with AI insecurity and is afraid of being left behind
shimman8 days ago
No, most workers don't really say this in surveys and polling. They tend to hate LLM tools because it makes their jobs worse, nothing about being left behind.

The only people pushing the "left behind" narrative is SV + SF + VC since their previous narratives have failed to persuade the public (thank fuck).

mattbrewsbytes8 days ago
This is kinda the reason why the Meta stock might be pumping and Muse might leap ahead other AI solutions as far as market share goes. Quoted from Prof G Markets podcast: "meta has been molesting your privacy for 10 years".

It stands to reason their daily active users just don't care, they are already sharing so much on Meta's platforms it won't matter to them.

imagetic8 days ago
We all fear the true answer to that question.
apazzolini8 days ago
> Who in their right mind would install a Meta AI

I fixed it for ya

yalok8 days ago
> macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device

Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…

corvad8 days ago
Click-bait title huh. This is not even close to a 0-day. I guess that word has lost all meaning to ArsTechnica huh.
TiredOfLife8 days ago
ars and the register have always been closer to the onion than journalism
sippingabonedry8 days ago
Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
NDlurker8 days ago
Why would they pay Muse? Muse the band doesn't have a monopoly on the word muse
dylan6048 days ago
because they had control of the handles used on Meta's apps. Why is that hard to understand. I was shocked they paid them instead of just taking it.
axus8 days ago
Did the band end up getting money for that?
echelon8 days ago
Presumably. They changed their handle on non-Meta social networks to match at around the same time as the Meta handle change.

Read the full thread on Hacker News →

Related stories