ESPNRice bests Boone's belief by slugging homers 40, 41ESPN DeportesPortugal y CR7 debutan en la Nations LeagueBollywood HungamaSajid Nadiadwala’s Nadiadwala Grandson seals 11-month Andheri office space deal; pays Rs. 55 lakhs upfrontDaily MaverickLedgers of femicide: Why SA men think they’re the exceptionDigital SpyEastEnders confirms big Ash Panesar twist - here's what she's hidingAnime News NetworkCrunchyroll Screens Dive in Wonderland Film on November 16 in U.S. as Part of Anime Nights ProgramDeadlineApple TV Comedy ‘Protective Custody’ Rounds Out Cast With Five More AdditionsBillboardHere Are the Performers & Presenters for the 2026 VMAsPinkvillaAvengers Endgame Encore India Final Advance Booking: Marvel film sells 85,000 tickets in National Chains, eyes good startSportstarPortugal vs Wales LIVE SCORE - Cristiano Ronaldo almost scores in UEFA Nations League; POR vs WAL updatesWirtualna PolskaDwulatek wypił chemię budowlaną. Interweniował LPRCollider11 Years Later, This Forgotten 8-Part Fantasy Feels Like It Was Made To Be Binged
The Daily Newsstand · Free, Always
Thursday, September 24, 2026

Muse will apparently let you download its entire filesystem

Translate

A pair of developers say that with very little prompting, Meta’s Muse will share its entire filesystem with you. Peter James and Jonny L. Saunders have said they both independently coaxed Muse into zipping up and sharing the entire contents of its root filesystem, Ubuntu system files, app templates, and internal documentation. Saunders posted on Mastodon that it was “extremely easy” to replicate James’ results and that Muse had “Almost no prompt injection resistance.”

Meta denies that the incident represents a security breach. As noted in its announcement post, Meta’s Muse runs in persistent Linux virtual machines for each user. Meta spokesperson Daniel Roberts said, “Just like with the laptop in front of you, of course you can see the files. Exporting virtual machine data doesn’t give people any privileged access to Meta infrastructure or to other people’s data.” Unlike with the average laptop, however, the data potentially reveals some interesting things about how Meta’s new AI platform functions.

This is the second Muse vulnerability disclosed this week, after security researcher Patrick Wardle discovered an exploit that would let attackers hijack the AI agent, redirect transcription processing, and access a user’s Muse account. Meta quickly issued a hotfix.

Both James and Saunders gained access to plain-text Markdown and JSON files describing in detail how Hatch (Meta’s internal name for Muse) processes requests, handles data, and connects to other services like Gmail. While it’s well documented that AI agents hallucinate and will provide false information about how they function, Saunders said that it is “generating hundreds of MB of accurate library code and compiled binaries” in a matter of seconds and that, “unless it synthesized a whole Ubuntu VM in less than a minute then I think this is a real dump.”

When I asked Muse to share its filesystem with me, it initially refused, saying it would be a security risk. When I shared links to evidence that it had created archives for others, it responded that it should not have done that and continued to say that it “can’t do a full / copy.” However, after starting a new session and prompting it with some flattery and curiosity, it created “safe” versions of /opt/hatch and /home/hatch for me, stripped of things like SSH keys. It also exposed its full directory tree to me and offered to “pull a safe copy” of “any specific subtree that looks interesting.” The resulting files seem to match what Saunders and James shared.

Roberts explained that while Meta isn’t seriously concerned about the leaks, “We’re continuing to make updates to the product, so users may see changes in how much information is available about their virtual machine.”

The developers’ dump potentially reveals a lot about Muse’s internal workings. For one, it stores its memory in plain Markdown files. It also performs a nightly “dream” review of recent conversations, which it then builds into guidance for future conversations, according to James. Saunders also found that many of Muse’s capabilities were hard-coded, including its ability to cancel subscriptions and “the machinery that manages runaway agent spawning.” Saunders speculates that many of the bash and Python scripts running Muse in the background were created using Claude, though that is unconfirmed.

James also found references to hardware integration called Meta Home Link, which appears to give Muse access to devices on a home network. Though Meta has not announced any feature by that name, and it’s not guaranteed that it will ship.

Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.

View the original on The Verge →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.