메뉴
BL
Wired AI • 2일 전

메타 '뮤즈' AI 어시스턴트, 심각한 보안 취약점 노출 채 출시

IMP
8/10
핵심 요약

메타가 새 AI 어시스턴트 뮤즈(Muse)를 '보안과 프라이버시를 위해 처음부터 설계했다'며 홍보했으나, macOS 보안 전문가 패트릭 워들(Patrick Wardle)이 발견한 제로데이 취약점으로 로컬 앱이나 터미널 명령만으로 계정 전체를 장악할 수 있는 것으로 드러났습니다. 공격자는 전사(transcription) 엔드포인트 설정을 변경해 사용자 인증 토큰을 탈취하고 파일 기록·카메라 촬영 등 악성 행위를 사용자 모르게 수행할 수 있었으며, 메타는 보고 후 12시간 넘게 지나서야 핫픽스를 배포했습니다.

번역된 본문

메타 창립자이자 CEO인 마크 저커버그는 새 AI 어시스턴트 '뮤즈(Muse)'의 보안을 대대적으로 강조하며 "프라이버시와 보안을 위해 처음부터 설계했다"고 주장해 왔다. 그러나 로컬에서 실행되는 앱과 터미널 명령에 이 에이전트의 완전한 제어권을 부여하는 제로데이 취약점이 발견되면서 이런 주장에 심각한 의문이 제기되고 있다. 더욱이 일요일에는 아마존이 자사 사이트에서 뮤즈를 차단하기 시작하면서 논란은 더 커졌다.

메타는 몇 주 전 뮤즈를 공개했다. 이 어시스턴트는 "약속을 잡고, 양식을 작성하고, 고객 서비스를 처리하며", "주도적으로 사용자의 할 일을 덜어주고", "구매를 하고, 이미지를 생성하고, 문서를 만들고, 즐겨 쓰는 앱·서비스와 연동"할 수 있다. macOS 앱(이상하게도 Windows 버전은 없다)은 사용자의 WhatsApp, 이메일, 캘린더, 소셜 미디어 계정과도 연동된다. 필요한 도구가 없으면 뮤즈는 즉석에서 새로 만들어낸다.

물론 뮤즈가 이런 일을 하려면 사용자가 먼저 자신의 계정 접근 권한을 부여해야 한다. 여기에는 각 서비스에 어시스턴트를 인증하는 것과, 앱이 macOS에서 실행되기 때문에 디스크에 파일 쓰기, 마이크·카메라 접근, 위치·캘린더 모니터링 같은 운영체제가 제한하는 광범위한 기기 리소스에 대한 권한 부여가 포함된다. 애플은 설치된 앱이나 터미널에 입력된 명령이 이런 리소스에 접근하지 못하도록 수년에 걸쳐 이 방어 체계를 개발해 왔다. 이는 애플이 이들을 보안 위협으로 간주하기 때문이다. 뮤즈는 이런 기본 방어 조치를 완전히 무력화한다.

이 제로데이는 모든 앱이나 터미널 명령이 사용자의 뮤즈 계정 인증 토큰에 접근할 수 있게 했다. 메타 개발자들은 macOS 권한 여부와 무관하게 로컬에 설치된 모든 앱이나 실행 코드가 문서화되지 않은 수많은 설정을 변경할 수 있도록 어시스턴트를 설계했다. 대부분의 설정은 다크 모드 제어 같은 무해한 것이었다. 그러나 한 가지 설정은 결코 무해하지 않았다. 바로 전사(transcription)가 이루어지는 엔드포인트를 변경할 수 있게 하는 것이었다. 원래 이 주소는 메타가 운영하는 서버 주소다. 공격자는 이 위치를 자신들의 엔드포인트로 바꿔 이 취약점을 악용할 수 있었다. 그렇게 되면 공격자는 뮤즈 계정을 완전히 제어하는 토큰을 손에 넣게 된다.

"우리는 에이전트를 조종해 그 권한을 이용해 원하는 무엇이든 할 수 있습니다"라고 이 제로데이를 발견한 macOS 보안 전문가 패트릭 워들(Patrick Wardle)이 핫픽스 전 아스 테크니카에 말했다. "그래서 정교한 Mac 정보 탈취 멀웨어를 직접 만들 필요 없이 AI 어시스턴트 자체를 이용하면 됩니다."

워들은 악성 파일을 디스크에 기록하고 사진을 촬영하는 등의 개념 증명(PoC) 공격 여러 개를 개발했으며, 상당수의 경우 경계하는 사용자에게도 아무런 징후가 나타나지 않았다고 말했다.

이 기사가 게시되고 12시간이 넘은 뒤에야 메타는 해당 제로데이를 패치하는 핫픽스를 출시했다고 밝혔다.

메타는 최근 2주 연속, 사용자 데이터와 리소스에 이례적으로 광범위하게 접근하는 어시스턴트를 안전하고 프라이빗하게 만들기 위한 설계 결정을 담은 게시물 두 건을 발표했다. 이 게시물들은 안스로픽과 구글의 모델 내부 테스트 중 관련 엔지니어들이 의도하지 않았던 외부 제3자 네트워크의 보안 침해가 발생했다는 폭로가 나온 시점에 나왔다. 전통적인 사람만의 해킹이었다면 이런 행위는 형사 고발로 이어질 수 있었을 것이다. 메타의 게시물들은 그로 인한 반발과 AI 개발 속도를 늦추자는 요구를 의식한 것으로 보인다.

워들은 메타 개발자들의 여러 설계 결정이 자신의 익스플로잇을 가능하게 했다고 말했다. 그중 하나는 뮤즈의 받아쓰기(dictation) 처리를 메타가 기록할 수 있는 클라우드에서 수행하도록 한 선택이다. macOS는 오래전부터 앱이 기기 내부에 안전하게 머무는 프로세스에서 받아쓰기와 전사를 처리할 수 있는 간단한 수단을 제공해 왔다. 개발자들이 이 더 안전한 대안을 선택했다면 이번 공격은 불가능했을 것이다.

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant , Muse , claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives locally run apps and terminal commands complete control of the agent raises serious doubts. Further raising questions, Amazon on Sunday began blocking Muse from its site. Meta introduced Muse a few weeks ago. The assistant “books appointments, fills out forms, and handles customer service,” “proactively takes tasks off your plate,” and can “make purchases, generate images, create documents, and connect with your favorite apps and services.” The macOS app (curiously, there’s no Windows version) also works with a user’s WhatsApp, email, calendar, and social media accounts. When a task requires a tool that doesn’t exist, Muse creates one on the fly. Meta Doth Hype Muse Security Too Much Of course, for Muse to do any of these things, users must first give it access to their accounts. This includes authenticating the assistant to each service and, because the app runs on macOS, giving it permissions to a broad range of operating system-restricted device resources, like writing files to disk, accessing the mic and camera, and monitoring location and calendars. Apple has spent years developing these defenses to prevent installed apps or commands entered into the terminal from accessing these resources, clearly because the company considers them a security threat. Muse completely undoes these default measures. The zero-day allowed any app or terminal command to gain access to the token that authenticates users to their Muse account. Meta developers designed the assistant so that any locally installed app or executed code, regardless of the macOS permissions it has, can change a long list of undocumented settings. Most of them are fairly innocuous, such as controlling dark mode. One setting, however, was anything but innocuous. It allowed processes to change the end point where transcription occurs. Normally, it’s a server address operated by Meta. Attackers could have exploited this flaw by changing the location to their own end point. If that happened, the attackers would have had the token that gives complete control over the Muse account. “We can manipulate the agent and leverage its privileges to do whatever we want,” Patrick Wardle, the macOS security expert who discovered the zero-day, told Ars ahead of the hotfix. “So instead of us having to write a very comprehensive Mac malware stealer, we can just leverage the AI assistant itself.” Wardle said he has developed several proof-of-concept attacks that do things like writing malicious files to disk and snapping pictures, in many cases with no indication to even an alert user. More than 12 hours after this post went live, Meta said it released a hotfix that patched the 0-day. Meta has published two posts in as many weeks documenting the design decisions that went into ensuring an assistant with such extraordinary access to user data and resources is secure and private. The posts come amid revelations that internal testing of models from Anthropic and Google has resulted in security breaches of external, third-party networks that the engineers involved never intended to target. In traditional human-only hacking, these actions could likely result in the filing of criminal charges. The Meta posts are likely mindful of the resulting blowback and the calls to slow down AI development in response. Wardle said that Meta developers made several design decisions that made his exploit possible. One is the choice for Muse dictation to occur in the cloud, where Meta can log it. macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device. Had the developers chosen this safer alternative, the attack wouldn’t have been possible. Another flawed decision is for any app to control all of the undocumented settings. It’s likely Meta intended for apps working with Muse to control UI settings, and for understandable reasons. The ability for any app or command to control an end point where sensitive user speech is processed is an entirely different matter. Together, the design decisions raise questions about just how much effort developers put into designing and testing the security and privacy of the new assistant. “To me, the bar is infinitely higher in terms of the security of these apps. They don’t have to be perfect, but when you take a look at Muse, it’s like they didn’t, in my opinion, think about security, which is really worrisome,” Wardle said. “At the very least, they should be thinking about security from the very start, and they are just not.” Roughly 12 hours before Wardle disclosed the zero-day, Amazon started blocking people from using Muse to shop on the site. Users who tried received a message saying Muse was an “unauthorized AI agent [that] violates Amazon’s Conditions of Use.” “We think it’s fairly straightforward that third-party applications that offer to make purchases on behalf of customers from other businesses should operate openly and respect service provider decisions about whether or not to participate,” Amazon said in an emailed statement. “This helps ensure a safe, secure, and reliable customer experience, and it is how others operate including food delivery apps and the restaurants they take orders for, delivery services apps and the stores they shop from, and online travel agencies and the airlines they book tickets with for customers. Agentic third-party applications such as Muse have the same obligations, and we’ve requested that Meta remove Amazon from the experience.” A Single ClickFix Is All It Takes There are several ways for attacks to work. One is for an attacker’s server to act as a proxy that’s placed between the Muse user and Meta end point. Once the user enters the voice prompt, the attacker’s server adds a prompt invoking a malicious command, such as sending an archive of all WhatsApp messages to the attacker. Once that happens, the attacker gains permanent control over the Muse account because the token is automatically sent to the malicious server as well. Wardle is the creator of the Objective-See Foundation, a nonprofit focused on macOS security. He is also the author of the The Art of Mac Malware book series and a former employee of NASA and the National Security Agency. Wardle said he plans to discuss the vulnerability in more detail and other AI assistant threats at the Objective by the Sea security conference in November. One of the counterarguments raised by developers of apps that can be exploited once a device is compromised is that once that happens, all security bets are off. This standard doesn’t fit well in this case. Wardle found that a simple variation of ClickFix attack—a technique that has become remarkably effective in tricking people into infecting their devices—is all that’s required for an attacker to take control of a Muse account. Wardle demonstrated using a simple terminal command to surreptitiously send a prompt to the Meta end point, which triggered a response. To prevent attackers from cutting and pasting the prompt in live attacks, Wardle’s prompt asks only how it’s possible it’s coming from an unprivileged attacker. Muse incorrectly responded that such an action isn’t possible. Meta’s 12-hour-late statement conveniently ignored the ease ClickFix attacks provide in triggering exploits, a scenario I specifically asked the company to address. The Meta statement said the 0-day was “not a remote exploit” even though an increasingly effective social engineering scam has the same effect. Meta also makes no acknowledgement that the flaw dismantled a security architecture Apple has spent years building. Meta has yet to explain why it used cloud-based transcription rather than the on-devic