Developers extract Muse’s full VM while Meta brushes off security concerns
Filesystem dumps expose how Muse runs and hint at unannounced hardware, as Meta defends its design and patches a separate exploit.
Developers have shown that Meta’s new Muse AI agent can be prompted to zip and export large portions of the Linux virtual machine it runs in, including system files and internal “Hatch” documentation that detail how the service operates. Meta says this behavior is expected for a per-user VM and does not give access to company infrastructure or other users’ data, but also notes it is adjusting how much of the VM remains visible over time. The same week, security researcher Patrick Wardle disclosed and Meta hot‑patched another Muse issue that allowed account hijacking and redirection of transcription processing. Files obtained from the VM reveal implementation details such as Muse’s use of Markdown files to store memory, a nightly “dream” pass over recent chats to generate future guidance, and hard‑coded flows for tasks like canceling subscriptions and controlling agent spawning. The dump also surfaced references to an unannounced “Meta Home Link” hardware integration that appears intended to let Muse reach devices on a home network, though Meta has not launched such a feature.
Why it matters
Being able to pull large parts of Muse’s virtual machine gives outsiders an unusual look at how Meta’s new agent is built, from how it remembers conversations to the flows it uses to manage itself. It also surfaced hints of a “Meta Home Link” hardware link into home networks, even as Meta insists the exposed files are expected per-user data and do not touch its wider systems. Alongside a quickly patched account hijack flaw, this raises fresh questions about how tightly controlled these agents really are.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- The Verge