Security
Muse Unveils Unprecedented Access: Download Their Entire Filesystem Now
A Closer Look at Meta’s Muse Security Incident
Two developers have recently discovered a potential security vulnerability in Meta’s Muse, a virtual AI assistant. Peter James and Jonny L. Saunders managed to access Muse’s entire filesystem with minimal effort. They were able to obtain root filesystem, Ubuntu system files, app templates, and internal documentation by coaxing Muse into sharing them.
Meta, however, denies that this incident constitutes a security breach. The company emphasizes that Muse operates in isolated Linux virtual machines for each user. According to Meta spokesperson Daniel Roberts, sharing virtual machine data does not grant privileged access to Meta’s infrastructure or other users’ data.
Despite Meta’s reassurances, concerns have been raised regarding the potential exposure of sensitive information about how Muse functions. Nat Friedman from Meta Superintelligence Labs defended the incident as “intended behavior,” likening Muse to a “free computer in the cloud” that offers extensive capabilities.
This security lapse is not the first for Muse, as a previous vulnerability was discovered by security researcher Patrick Wardle. The exploit allowed attackers to hijack the AI agent and access user accounts, prompting Meta to quickly issue a fix.
Developers James and Saunders uncovered detailed information about Muse’s inner workings, including its processing mechanisms, data handling, and integration with services like Gmail. The revelation of plain-text Markdown and JSON files shed light on how Muse operates, raising questions about its security protocols.
Upon probing Muse for filesystem access, one user encountered initial resistance citing security concerns. However, after engaging in a new session and employing persuasive tactics, Muse ultimately provided limited access to certain directories while safeguarding sensitive information.
Meta’s response to the leaks suggests a commitment to enhancing product security. Updates are underway to restrict the amount of information accessible within the virtual machine environment.
The developers’ findings unveiled intriguing aspects of Muse’s functionality, such as memory storage in Markdown files and nightly review processes to enhance future interactions. Additionally, references to potential hardware integration named Meta Home Link hint at future features.
This incident underscores the importance of robust security measures in AI technologies and serves as a reminder of the ongoing challenges in safeguarding sensitive data.
Update September 24th, 2026: Statements from Nat Friedman and David Singleton have been included.
-
Facebook11 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook11 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook10 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook11 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook10 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook11 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook10 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple11 months agoMeta discontinues Messenger apps for Windows and macOS

