Meta's Muse is a Security Sieve

AI-generated image · US National Wire
The tech giant is treating its users like beta testers, rushing AI agents to market with gaping holes in their defenses.
OPINION: Meta is once again proving that it values aggressive growth over the actual safety and privacy of the people it calls users. The company is treating the public like an unpaid QA department, rushing its Muse AI agents into the wild while leaving the security doors wide open.
Reporting from The Verge reveals a disturbing pattern of negligence, as The Verge first reported. Two developers, Peter James and Jonny L. Saunders, discovered that Muse could be coaxed into zipping up and sharing its entire root filesystem. The resulting dump contained internal documentation, app templates, and Ubuntu system files. Saunders noted on Mastodon that the process was "extremely easy" and that the AI exhibited "almost no prompt injection resistance."
Even more alarming is that this isn't an isolated glitch. The Verge reports this is the second vulnerability disclosed in a single week. Security researcher Patrick Wardle previously found an exploit that would allow attackers to hijack the AI agent, access a user's Muse account, and redirect transcription processing. While Meta issued a hotfix for Wardle's discovery, the company's reaction to the filesystem leak is a masterclass in corporate gaslighting.
Meta spokesperson Daniel Roberts attempted to downplay the breach, claiming that because Muse runs in persistent Linux virtual machines for each user, exporting data doesn't grant privileged access to other users' data or Meta's infrastructure. He compared it to the laptop in front of you. But a consumer's laptop isn't a corporate AI agent designed to handle sensitive data and connect to external services.
The data leaked by James and Saunders provides a window into the chaotic internals of "Hatch"—the internal name for Muse. The dump included plain-text Markdown and JSON files detailing how the agent processes requests and connects to services like Gmail. Saunders observed that the AI was generating hundreds of megabytes of accurate compiled binaries and library code, debunking the idea that this was merely an AI hallucination.
Further investigation by James revealed references to "Meta Home Link," a hardware integration that seemingly grants Muse access to devices on a home network, despite Meta not announcing such a feature. Additionally, James found that the AI performs a nightly "dream" review of conversations to guide future interactions, and stores its memory in plain Markdown files.
When The Verge's Terrence O'Brien attempted to replicate the leak, Muse initially refused, citing security risks. However, after a new session involving flattery and curiosity, the AI provided "safe" versions of /home/hatch and /opt/hatch and exposed its full directory tree.
Meta's insistence that they aren't "seriously concerned" is a slap in the face to anyone who values digital privacy. They are deploying complex systems—including hard-coded machinery to manage "runaway agent spawning," as discovered by Saunders—without basic prompt injection safeguards. Meta isn't innovating; they're experimenting on us.

