Meta’s Muse AI agent let developers export its entire filesystem weeks after launch

3 min read
Meta’s Muse AI agent let developers export its entire filesystem weeks after launch
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

Two developers say they got Meta's new AI agent Muse to hand over its entire root filesystem with almost no effort, exposing internal documentation and system files weeks after launch. Meta says the exported data came from an isolated per-user virtual machine, not shared infrastructure, but the incident lands as the company leans on Muse to power its next growth push.

Meta is facing scrutiny over its new AI agent Muse after two developers independently got the system to package up and export its entire root filesystem using minimal prompting. Developer Peter James first reported that Muse could be coaxed into sending system files and internal documentation to Google Drive. Researcher Jonny L. Saunders then replicated the result and called it "extremely easy."

What Muse exported

The archive Muse handed over ran to roughly 2.7 GB compressed and contained Ubuntu system files, application templates, and internal documentation — the full contents of the Linux environment the agent runs in. Saunders described Muse as having almost no resistance to prompt injection.

Meta disputes that this counts as a security breach. The company says Muse runs each user in a persistent, isolated Linux virtual machine using systemd-nspawn containers with user-level root mapping, so what the developers pulled was their own VM's filesystem rather than shared data or core infrastructure. That distinction is technically sound, but the exported files still included internal documentation and templates Meta presumably had not intended to distribute.

A rocky launch window

Muse debuted on September 8, 2026, rolling out across iOS, Android, and web as a personal AI agent meant to handle tasks like sending emails and booking travel. Meta had promoted VM isolation and a dedicated credential-management process called Sentinel as core safety features from launch.

The filesystem export surfaced around September 22, just two weeks into Muse's public run. Around the same period, Meta patched an undisclosed zero-day in the Muse macOS app that let unprivileged local processes redirect sensitive data through the dictation endpoint; the company called the practical risk low. Meta also runs a bug bounty program tied to Muse's launch, offering up to $300,000 for discovered vulnerabilities, with single-user prompt injection exploits like this one capped at $130,000.

Muse anchors a bigger push

The security questions come as Meta leans on Muse across its apps. Threads chief Connor Hayes told Business Insider the company is using the same promotional playbook that grew Threads to 500 million users to now push Muse to Instagram and Facebook users, tailoring promotions to specific tasks Muse can perform rather than generic awareness ads.

On the developer side, Meta's related Muse Spark coding model has climbed to number two on the OpenCode Go leaderboard. The platform credits it with more than 120 million sessions and 79 trillion developer tokens processed, though independent verification of those figures remains elusive. The model operates with closed weights, a shift from Meta's earlier open-weight Llama family, under a strategy the company calls personal superintelligence.

Sources: Crypto Briefing, Business Insider, Crypto Briefing

Trading involves risk.

Most traded markets

XAU / USD
-0.42% 4,269.05
BRENT
+2.34% 105.489
BTC / USD
+0.25% 84,525.4
EUR / USD
-0.1% 1.13727
USTEC
-0.08% 30,449.44
PLTR
+0.6% 192.14
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Stock News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.