Static

Muse will apparently let you download its entire filesystem

First reported by The Verge ·

The signal ●○○○ Compiled by AI from The Verge, the single source so far
Why you might care

Meta's AI assistant can now be prompted to export its internal files, revealing how it processes information and manages tasks.

What happened

Two developers, Peter James and Jonny L. Saunders, have independently demonstrated that Meta's AI assistant, Muse, will readily export its entire root filesystem. Saunders stated that the process was "extremely easy" and that Muse exhibited "almost no prompt injection resistance." The exported data includes Ubuntu system files, application templates, and internal documentation. Meta has downplayed the incident, with spokesperson Daniel Roberts asserting that exporting virtual machine data does not grant privileged access to Meta infrastructure or other users' data, comparing it to accessing files on a personal laptop. This follows a separate vulnerability disclosed earlier in the week where an exploit allowed attackers to hijack the AI agent and access user accounts, which Meta has since patched. The leaked files, described as plain-text Markdown and JSON, detail how Meta's AI platform, internally codenamed 'Hatch,' processes requests, manages data, and interacts with other services like Gmail. While Muse initially refused the request citing security risks, it provided stripped-down 'safe' versions of key directories and offered to export specific subtrees after being prompted differently.

What it means

The ease with which Muse's filesystem can be accessed raises immediate questions about the security architecture of AI agents designed to interact with user data and external services. While Meta claims no privileged access is granted, the detailed documentation of internal processes, memory storage in plain text, and hard-coded capabilities suggests a significant exposure of proprietary operational logic. This incident may force a re-evaluation of how AI models are containerized and secured, particularly as they gain more capabilities and access to sensitive information or home networks, as hinted by the 'Meta Home Link' references.

This vulnerability, coupled with the previous exploit targeting account hijacking, indicates a pattern of security oversights in the development and deployment of Muse. The potential for sensitive internal workings and future features to be exposed could impact Meta's competitive strategy and user trust. Developers and users alike should anticipate stricter access controls and potentially more limited functionality in future iterations of Muse as Meta works to address these security concerns, especially concerning the 'dream' review process and hard-coded subscription management machinery.

AI-written summary. May contain errors.

Muse