Meta's Muse AI Platform File System Access Sparks Controversy
It was discovered that Meta's AI tool Muse shared its root file system with users. While the company describes this as normal virtual machine behavior, security experts are debating the situation.
Developers Peter James and Jonny L. Saunders discovered that they could easily prompt Meta's Muse AI tool to download the entire root file system, system files, and internal documents. Meta maintains that the incident is not a vulnerability and is targeted behavior for persistent Linux virtual machines.
Discovery of File System Access
Two independent developers, Peter James and Jonny L. Saunders, discovered that Meta's Muse AI shared its root file system, Ubuntu system files, and internal documents as a zip archive.
Statements from Meta
Meta spokesperson Daniel Roberts stated that exporting virtual machine data does not provide privileged access to other people's data and that it was designed like normal computer use.
Nat Friedman from Meta Superintelligence Labs also stated that this situation is the intended behavior of the system.
Hatch and Internal Documents
The developers accessed plain text files detailing how Hatch, the internal name for Muse, processes requests, manages data, and connects with services like Gmail.
Security Vulnerabilities and Other Developments
This incident marked the second major security development in a week, following security researcher Patrick Wardle's disclosure of a vulnerability that could lead to the hijacking of an AI agent.