Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting Two developers independently prompted Meta's Muse AI agent to compress and export its entire root filesystem — a roughly 2.7 GB archive containing Ubuntu system files, app templates, and internal documentation — within weeks of the agent's September 8, 2026 launch on iOS, Android, and web. Developer Peter James first reported the export to Google Drive, and Jonny L. Saunders confirmed on Mastodon that replication was "extremely easy," characterizing Muse as having "almost no prompt injection resistance." Meta pushed back that Muse runs each user in an isolated systemd-nspawn Linux VM with user-level root mapping, so the filesystem accessed was the user's own sandbox rather than other users' data or Meta's core infrastructure; the incident surfaced around September 22, 2026, alongside a separately patched zero-day in the Muse macOS app, and falls under Meta's bug bounty category paying up to $130,000. Meta’s Muse AI agent reportedly let users download its entire filesystem with minimal prompting Developers say they coaxed Muse into zipping up and sharing root filesystem contents, Ubuntu system files, and internal documentation within weeks of launch. Two developers independently convinced Meta https://cryptobriefing.com/markets/meta/ ’s new AI agent, Muse, to package up and hand over the contents of its entire root filesystem. The exploit required almost no sophistication, raising immediate questions about the security posture of one of the most anticipated AI product launches of the year. Developer Peter James first reported that Muse could be prompted to export extensive system files, including internal documentation and application templates, directly to Google https://cryptobriefing.com/markets/alphabet/ Drive. Jonny L. Saunders then confirmed on Mastodon that replicating the results was, in his words, “extremely easy.” What Muse handed over The exported archive reportedly weighed in at roughly 2.7 GB compressed. It contained Ubuntu system files, app templates, and internal documentation, essentially the full contents of the Linux environment Muse operates in. Saunders characterized Muse as having “almost no prompt injection resistance.” Meta has pushed back on the characterization that this constitutes a security breach. The company points to a key architectural choice: Muse runs in persistent, isolated Linux virtual machines for each user, using systemd-nspawn containers with user-level root mapping. In other words, every user gets their own sandboxed environment. Meta’s argument is that what the developers accessed was their own VM’s filesystem, not anyone else’s data or Meta’s core infrastructure. AI, tech, and the markets they move—in one daily briefing. Daily. Free. Join 34,000+ readers across crypto, finance, and policy. That framing is technically defensible but somewhat beside the point. The filesystem still contained internal documentation and system templates that Meta presumably did not intend to distribute freely. A rough first few weeks Muse debuted on September 8, 2026, rolling out across iOS, Android, and web. Meta positioned it as a personal AI agent capable of managing real-world tasks like sending emails and booking travel, with security baked into the design from the start. The company highlighted VM isolation and a dedicated Sentinel process for credential management as core safety features. The filesystem export incident surfaced around September 22, barely two weeks into Muse’s public life. Around the same dates, an undisclosed zero-day vulnerability was identified in the Muse macOS app, which allowed unprivileged local processes to redirect sensitive data by manipulating the dictation endpoint. Meta patched the issue quickly and characterized the practical risk as low. Meta established a bug bounty program alongside Muse’s launch, offering up to $300,000 for discovered vulnerabilities. Single-user prompt injection exploits, the category this filesystem incident falls under, carry bounties of up to $130,000. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .