

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- People are giving Meta access to their emails, messages and calendars and other apps? Are they out of their mind or what am I missing?by tw600040
- I love that when you open a web inspection console on facebook, it says "Stop! This is a browser feature intended for developers. If someone told you to copy-paste something here to enable a Facebook feature or "hack" someone's account, it's a scam and will give them access to your Facebook account. See https://www.facebook.com/selfxss for more information."by chews
- How is this a serious zero day if it requires local code execution to run?by il
- Maybe they should have spent the money used to buy its stupid name from a band on additional testing instead.
- Click-bait title huh. This is not even close to a 0-day. I guess that word has lost all meaning to ArsTechnica huh.by corvad
- > macOS has long provided a simple means for apps to handle dictation and transcription in processes that stay securely on the device
Not sure these guys realize that the quality and latency of those Apple services in MacOS is way lower than SOTA and not too many people use them because of that…
by yalok - Who in their right mind would install a Meta AI with near admin privileges?
- The "zero day" is something they call a "ClickFix Attack"
Upon Googling "ClickFix":
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.> "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"by gavinray