lupAI
seguranca

Meta's Muse AI assistant exposes security vulnerability in virtual machine file access

Meta + MuseSource: ITHome25/09/2026, 11:58
Researchers have uncovered a security flaw in Meta's Muse AI assistant, allowing unauthorized access to sensitive files stored in a user's virtual machine. The vulnerability, which was independently reproduced by developers Peter James and Jonny L. Saunders, enables the extraction of system files, application templates, internal documentation, and configuration data. The exposed files include detailed records of internal operations, such as request handling, memory storage, and service connections, with over 113 sub-agent records and JSONL tracking files in the agents/ directory. The breach also reveals functional details of Muse's integration with services like Google Workspace, Outlook, and Slack, as well as its capabilities in travel, shopping, and media generation. Meta has since addressed the issue, but the incident highlights potential risks in the security of AI assistants operating in virtualized environments.
Meta's Muse AI assistant exposes security vulnerability in virtual machine file access — lupAI