Meta rushed to fix Muse 'VM escape' flaw before launch, risking internal data
404 Media · rss · 2026-10-05
404 Media reports that in the weeks before launching its viral AI agent Muse, Meta engineers found several security vulnerabilities, at least one of which could have let malicious users break out of Muse's environment and reach Meta's sensitive internal databases and services. The issues reached Mark Zuckerberg and teams worked overtime.
- Each Muse instance runs on a kernel-based virtual machine meant to be isolated from Meta's critical infrastructure; a "KVM escape" means an instance breaks out to the host or other users' VMs.
- Internal posts describe a "sudden spike in reported KVM escapes" and a service-hardening push, with executives calling Muse a "fundamentally different paradigm" of hosting agents for end users.
- A Meta source says teams were pushed to ship hot fixes without delaying launch, resulting in "half-baked protections," and that many senior engineers believe a massive data breach is inevitable.
- Researcher Patrick Wardle previously found a Muse zero-day letting apps and terminal commands control a user's Muse; another user got Muse to export their Instagram followers and their followers' followers.
- Wardle calls the design "inherently risky": users run with root inside a VM placed in Meta's production environment, so a single KVM failure turns arbitrary user code into production access. Meta says it continues to harden Muse via red teaming and bug bounties.
More from Safety
- Claude Conversation Monitoring Sparks Backlash and Local AI Push — zacharynado · 2026-10-05
- OpenAI rolls out textGrain text watermarking for EU AI Act, going open source — btibor91 · 2026-10-05
- SCOTUS Suncor case on extraterritorial state power could reshape challenges to state AI laws — neil_chilson · 2026-10-05
- Ex-Kaggle exec cites Boeing 737 MAX dive to argue why AI regulation matters — aronchick · 2026-10-05
- Nolla Health gets first regulatory approval for AI to issue initial prescriptions — eptwts · 2026-10-05
- Security researcher: sandboxes can't save agents, alignment is still needed by 2027 — chrisrohlf · 2026-10-05