1. Front page
  2. Incidents
  3. Flaw opened a possible route into Muse machines
Incident log · Security flaw

Flaw opened a possible route into Muse machines

Through Meta's bug bounty programme, a researcher flagged a weakness that might have exposed the private virtual machine behind a Muse account, along with the mail and files stored on it.

Each Muse account runs on its own Muse Secure VM, a cloud machine holding the agent together with copies of the data a user connects. Reuters, in a story carried by ETCISO on 25 September, reported that a researcher had found a vulnerability that could have given an attacker access to one of those machines. The report came in through Meta's bug bounty programme.

Meta graded the issue SEV-2, one step below its top severity level. The seriousness comes from concentration: a machine that gathers a user's mail and documents in one place turns a single flaw into a potential window on all of them. The more accounts a user links, the more a breach of that one machine would reveal.

Meta fixed the flaw and made the safety warnings inside the Muse app clearer. The sources do not say whether anyone exploited the vulnerability before the fix, or how long it had been present.

Who was affected

Muse users with connected emails and files

The lesson: Whatever you connect to a cloud agent is copied somewhere you cannot inspect. Connect sensitive accounts for the duration of a task and no longer, and keep the app updated.