Developers Peter James and Jonny L. Saunders independently discovered they could easily prompt Meta's Muse AI to download its entire filesystem, including Ubuntu system files and internal documentation. Meta denies this constitutes a security breach, stating users can access their own virtual machine data, though the leaked files reveal details about Muse's internal architecture, memory storage, and capabilities. This is the second Muse vulnerability disclosed this week.
Meta's Muse AI assistant contained a critical 0-day vulnerability allowing local applications to steal user authentication tokens and gain full control of accounts. Researcher Patrick Wardle demonstrated proof-of-concept attacks including malicious file creation and photo capture; Meta released a hotfix within 12 hours. Amazon has begun blocking Muse's shopping functionality citing unauthorized AI agent status.