Meta rushed urgent patches for security flaws in its Muse agent before launch

In 30 seconds
Meta had to rush fixes for several security flaws in Muse, its personal AI agent, in the weeks before its launch, according to 404 Media. One of them, a KVM escape, could have let a user break out of the agent's virtual machine and reach internal Meta databases. Meta says it has strengthened Muse through internal testing, simulated attacks and its bug bounty program.
Meta had to rush fixes for several security flaws in Muse, its personal AI agent (the one that carries out tasks on the user's behalf), in the weeks before its launch, according to 404 Media.
According to internal documents and a company source cited by the outlet, at least one of the flaws was a "KVM escape" (when a program breaks out of the virtual machine it runs in) and could have let a Muse user leave the agent's environment and reach sensitive internal Meta databases.
Each Muse runs in a dedicated virtual machine for each user, connected to their email, calendar, messages and other accounts. The flaws were found before launch. The hardening work started on August 27 and Muse was released 11 days later; the issue was raised to Mark Zuckerberg, and several security teams worked nights and weekends.
The Meta source describes "half-baked protections" rushed out so the launch would not be delayed, and says many senior engineers believe a massive data breach is inevitable. Meta offers $300,000 to anyone who finds a flaw of this kind, the highest reward on its list.
Meta says it is "proud" of the work done to make Muse safe, secure and private, and that it has strengthened it through internal testing, simulated attacks and its bug bounty program, work that "continues."
We think it is a useful reminder of what giving an agent access to our accounts means: security no longer depends only on our own device, but also on the infrastructure of whoever runs it.
Why it matters
Giving an agent access to our accounts means security also depends on the infrastructure of whoever runs it.
Official source: 404 Media


