Story
September 26, 2026
Meta Says Muse’s ‘Leak’ Was Really Your Cloud Computer
Developers thought Muse had exposed sensitive internal files with almost no resistance. Meta insists the downloads are intentional: each user’s persistent virtual machine is meant to function as their own Linux computer in the cloud.
The alarm began when developers Peter James and Jonny L. Saunders independently persuaded Meta’s new Muse agent to package and share the contents of its root filesystem. The material reportedly included Ubuntu files, app templates and internal documentation, while Saunders said reproducing the result was “extremely easy” and that Muse had “Almost no prompt injection resistance.”1
That discovery landed against an already awkward backdrop. Earlier that week, security researcher Patrick Wardle disclosed a separate exploit that could hijack the agent, redirect transcription processing and access a user’s Muse account; Meta issued a hotfix. In the filesystem case, however, Meta rejected the breach framing. Spokesperson Daniel Roberts said the files belonged to a persistent Linux virtual machine assigned to each user: “Just like with the laptop in front of you, of course you can see the files.” Exporting them, he added, provided no privileged access to Meta infrastructure or other users’ data.1
The next day, Meta’s product behavior made that argument more explicit. Where Muse had initially been reluctant to provide a complete archive—at one point invoking security concerns—it began offering a clickable browser with root access and readily zipped the root directory, while saying secrets had been stripped out.2
Meta Superintelligence Labs’ David Singleton characterized the change not as a retreat after an exposure, but as confirmation of the design: “your Muse Secure VM truly is your own computer in the cloud.”2 That puts the company at odds with the developers’ interpretation. They saw an agent revealing unusually rich operational detail; Meta sees a user inspecting the machine it was promised. The unresolved question is why Muse itself initially treated the request as forbidden if that openness was always intended.2