The "zero day" is something they call a "ClickFix Attack"
Upon Googling "ClickFix":
> "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
We filed a bug report but the original maintainer seems to have dropped offline. The community's had some success in correcting bugs with low-level hacking, but it's hard to make progress without the source code.
The exploit is a local zero day exploit, meaning the machine needs to already be compromised. For it to be a remote zero day exploit you need to do the ClickFix attack. The idea is that it lets you access much more machines and resources if the one machine with Muse is compromised. More info here: <a href="https://x.com/dps/status/2102248329111634067" rel="nofollow">https://x.com/dps/status/2102248329111634067
gavinray · · focus · HN ↗
Upon Googling "ClickFix":
I'm sorry, that's not a zero-day, that's idiocy that's as old as time.failbuffer · · focus · HN ↗
theultdev · · focus · HN ↗
clickbait headline should be changed, not a 0-day.
lirolero · · focus · HN ↗
[dead]
bigfishrunning · · focus · HN ↗
analog31 · · focus · HN ↗
bachittle · · focus · HN ↗
dspillett · · focus · HN ↗
> […] that's idiocy that's as old as time.
And constantly being reinvented: `curl -sL some.unverified.stuff.sh | bash`