Vulnerability was discovered in Meta’s Muse AI agent before launch and hastily fixed - media
Kyiv • UNN
Meta engineers found vulnerabilities in Muse that could have allowed escape from the virtual machine and access to internal databases. Security teams urgently fixed the issues before launch.

Several weeks before the launch of Meta’s personal AI agent Muse, Meta engineers discovered several vulnerabilities in the security system of the company’s viral product. At least one of them could have allowed attackers to escape the environment designated for Muse and gain access to confidential Meta databases and services. 404 Media learned of this, reports UNN.
The problems were reportedly so serious that they reached Mark Zuckerberg, and employees worked overtime to fix them.
Details
These specific vulnerabilities were discovered before the product’s launch, but required a "frantic race" by several teams to address a "sudden surge in reports of KVM escapes," according to an internal message from Meta team leaders to the core infrastructure team, seen by 404 Media.
To use Muse, a user gives the AI agent access to various important services and accounts they own. On Meta’s side, each individual Muse instance runs on a kernel-based virtual machine that connects to Meta’s own critical infrastructure but is supposed to be isolated from it. A "KVM escape" is when a Muse instance, using a vulnerability in the security system, can break out of the virtual machine and interact with the system on which it is running or with other users’ virtual machines.
According to a Meta source, as well as internal security documentation and internal messages reviewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker—that is, an ordinary Muse user—to gain access to data in confidential internal Meta databases. At least one of the vulnerabilities was related to an exploit discovered in the code of the Linux kernel-based virtual machine in July.
Some of the vulnerabilities were discovered in the underlying Linux virtualization software that Meta uses for Muse. The security issue was deemed serious enough to be brought to Mark Zuckerberg’s attention, and several different groups of security specialists worked nights and weekends ahead of the launch to fix the problems. Such heightened security measures before the launch of a major product are not unusual, but are notable given that outside researchers discovered several other security issues after Muse launched, as well as in the broader context of large-scale hacker attacks by AI agents from OpenAI and other companies, the publication notes.
A source at Meta said that, in their view, security specialists were required to release fixes for these bugs as quickly as possible without delaying Muse’s launch, which resulted in what they described as "a hastily released, insufficiently thought-out solution to ensure the launch. Many leading engineers believe that a major data breach at Hatch is inevitable." Within the company and in Meta’s codebase, Muse is called "Hatch."
A Muse virtual machine escape is potentially a very serious security issue and is classified as such in Meta’s bug bounty program. The company says it is prepared to pay $300,000 to any security researcher who discovers a bug that allows an escape from the virtual machine—the maximum payout listed on the bug bounty program’s website, the publication reports.