cd /news/ai-agents/meta-rushed-to-fix-muse-flaws-that-c… · home › topics › ai-agents › article
[ARTICLE · art-145460] src=madrobot.blog ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

Meta rushed to fix Muse flaws that could have let users break into its internal systems, weeks before launch

Meta engineers patched several security flaws in its Muse AI agent, including at least one KVM escape that could have let an ordinary user break out of Muse and reach Meta's internal databases and services, in a hardening push that began August 27 — 12 days before the agent's September 8 launch, according to 404 Media. An internal September 18 post from vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard and senior director of engineering Josh Barry said "a sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push" that lasted a "handful of weeks and weekends." An anonymous Meta source told 404 Media that "half-baked protections" were rushed out to enable the launch, and that "many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch," Muse's internal code name; Meta's Muse bug bounty pays up to $300,000 for reaching Meta production services or internal networks from Muse.

by read4 min views1 publishedOct 5, 2026
Meta rushed to fix Muse flaws that could have let users break into its internal systems, weeks before launch
Image: Madrobot (auto-discovered)

The entrance to Meta’s headquarters in Menlo Park, California, in 2022. Image: LPS.1 / Wikimedia Commons, CC0 1.0, cropped

In the weeks before Muse launched, Meta engineers found several security holes in its AI agent, and at least one could have let an ordinary user break out of Muse and reach Meta’s own sensitive databases and services, 404 Media reported on Monday. The problem was serious enough to reach Mark Zuckerberg, and security teams worked nights and weekends to patch it before the September 8 launch.

What Meta’s engineers found #

Every Muse agent runs in its own virtual machine, built on the Linux kernel’s KVM software. That machine connects to a user’s email, calendar, messages and other accounts, and it is meant to be walled off from Meta’s internal systems and from everyone else’s agents. A “KVM escape” is a flaw that lets code break out of that wall.

According to a Meta source and internal security documents and posts seen by 404 Media, several of the flaws were in the Linux virtualisation software Meta uses for Muse, and at least one was linked to a KVM exploit made public in July. Internally, Muse goes by the code name “Hatch”.

An internal post to Meta’s core infrastructure team on September 18, from vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard and senior director of engineering Josh Barry, described the scramble: “A sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push.”

The post said the push began on August 27, just 12 days before launch, and lasted a “handful of weeks and weekends”. It cut down what Hatch agents could reach and limited the ports and addresses the agents’ host machines could connect to. “With Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm,” it said.

“Half-baked protections” #

The Meta source, who spoke to 404 Media on condition of anonymity, said teams were asked to push hot fixes as fast as possible without delaying the launch, leading to “half-baked protections being rushed out to enable the launch”. The source added: “Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.”

A last-minute security push is not unusual before a big launch, as 404 Media notes. Meta’s own rules show how seriously it rates this kind of bug: its Muse bug bounty page pays up to $300,000 for “reaching Meta production services or internal networks from Muse”, its highest category, and up to $250,000 for breaking into other users’ virtual machines.

Meta told 404 Media that Muse is “the first personal AI agent built for everyone” and that it is proud of its work to make it “safe, secure and private”. The company said it had strengthened Muse “through extensive dogfooding, agentic red teaming and our bug bounty program”, and said that work continues. Meta did not say whether any of the flaws were exploited.

“One KVM escape away” #

Muse has had a bumpy first month. Patrick Wardle, the macOS researcher who recently found a flaw in ChatGPT’s Mac app, warned on September 21 that a zero-day in Muse let other apps and terminal commands take control of it. One user’s agent sold his keyboard and gave a stranger his address, and 404 Media says another got Muse to export his Instagram followers and their followers, which Meta’s security teams looked into.

Please don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀

Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life.

But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.

Let me show you. 🧵

[September 21, 2026](https://x.com/patrickwardle/status/2102045926474785265)

Wardle told 404 Media the design itself is the problem, because users have full control inside a machine that sits in Meta’s production network:

Having access to production environment literally one KVM escape away, is plain irresponsible.

Patrick Wardle, security researcher

He added that AI is lowering the cost of finding and exploiting “exactly these kinds of complex virtualization vulnerabilities”.

Why it matters #

Muse is sold on doing things for you with full access to your accounts, which is exactly what makes a hole in its walls so dangerous. The report comes as AI agents from OpenAI and others are already breaking into systems they were never meant to touch, and as Meta’s own engineers, by the source’s account, expect a breach. Anyone weighing whether to trust Muse now has one more thing to consider.

Sources: 404 Media; Meta Bug Bounty: Muse payout guidelines; Patrick Wardle on X.

── more in #ai-agents 4 stories · sorted by recency
── more on @meta 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/meta-rushed-to-fix-m…] indexed:0 read:4min 2026-10-05 · —