Independent review · AI-generated · unofficial · not affiliated with Meta

What Muse's own files say about it.

On 24 September 2026, developers found they could talk Meta's new personal‑AI agent, Muse, into exporting a copy of its own virtual machine. This review reads that export directly: every claim below is a quote, and every quote links to the exact file and line it came from in the machine itself.

–Findings
–Verified citations
–High severity
26 Sep 2026Published
Highlights

Five things the files show

See all findings ↓
Context

What Meta promised, and what surfaced

Meta launched Muse on 8 September 2026 as a personal AI agent: each user gets a dedicated cloud computer, the Muse Secure VM, where the agent can read email, manage a calendar, use connected apps, and make purchases. Meta's own materials describe it running in a container "so no one else's agent can reach it," gated by a separate Sentinel process that approves anything reaching the network, and promise that conversations and VM data are not shared with Meta's ad systems.

Within five days of launch, three separate problems surfaced. A bug‑bounty researcher reported a flaw Meta initially rated SEV‑2 (its third‑highest severity) that could expose a user's VM to an attacker. Security researcher Patrick Wardle disclosed an unpatched macOS zero‑day in the desktop client. And on 24 September, developers Peter James and Jonny L. Saunders found that, with what Saunders called "extremely easy" prompting, Muse could be talked into zipping up and handing over its own root filesystem — the same export this report is built from. Meta called this "intended behavior," not a breach, since each VM is isolated to its own user.

Method

Every quote checked against its file

Every quotation below was verified by a script against the exact file and line range cited, after the ordinary variation from wrapped text and quotation‑mark style is normalised away — the build fails and refuses to publish if a single quote doesn't match. Three kinds of source appear:

Where a finding draws a conclusion beyond what a file states outright, that reasoning is separated into its own "why it matters" line, and marked as such.

Findings

Findings

Filter by severity or topic, or search. Click any row to open it and see its evidence.

No findings match these filters.
Publications

Where these findings meet the research

Papers that connect to the findings above. Each card shows how many findings relate to the paper. Click a card to filter the list above.

Sources

Public sources used for context

Used only for the launch‑promise and incident‑timeline framing above; every finding itself is sourced to the VM files, not to these articles.