{"slug": "meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal", "title": "Meta rushed to fix Muse flaws that could have let users break into its internal systems, weeks before launch", "summary": "Meta engineers patched several security flaws in its Muse AI agent, including at least one KVM escape that could have let an ordinary user break out of Muse and reach Meta's internal databases and services, in a hardening push that began August 27 — 12 days before the agent's September 8 launch, according to 404 Media. An internal September 18 post from vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard and senior director of engineering Josh Barry said \"a sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push\" that lasted a \"handful of weeks and weekends.\" An anonymous Meta source told 404 Media that \"half-baked protections\" were rushed out to enable the launch, and that \"many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch,\" Muse's internal code name; Meta's Muse bug bounty pays up to $300,000 for reaching Meta production services or internal networks from Muse.", "body_md": "The entrance to Meta’s headquarters in Menlo Park, California, in 2022. Image: [LPS.1](https://commons.wikimedia.org/wiki/File:Meta_Platforms_Headquarters_Menlo_Park_California.jpg) / Wikimedia Commons, CC0 1.0, cropped\n\nIn the weeks before Muse launched, Meta engineers found several security holes in its AI agent, and at least one could have let an ordinary user break out of Muse and reach Meta’s own sensitive databases and services, [404 Media reported on Monday](https://www.404media.co/meta-rushed-to-fix-muse-vm-escape-vulnerability-immediately-before-launch/). The problem was serious enough to reach Mark Zuckerberg, and security teams worked nights and weekends to patch it before the September 8 launch.\n\n## What Meta’s engineers found\n\nEvery Muse agent runs in its own virtual machine, built on the Linux kernel’s KVM software. That machine connects to a user’s email, calendar, messages and other accounts, and it is meant to be walled off from Meta’s internal systems and from everyone else’s agents. A “KVM escape” is a flaw that lets code break out of that wall.\n\nAccording to a Meta source and internal security documents and posts seen by 404 Media, several of the flaws were in the Linux virtualisation software Meta uses for Muse, and at least one was linked to a KVM exploit made public in July. Internally, Muse goes by the code name “Hatch”.\n\nAn internal post to Meta’s core infrastructure team on September 18, from vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard and senior director of engineering Josh Barry, described the scramble: “A sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push.”\n\nThe post said the push began on August 27, just 12 days before launch, and lasted a “handful of weeks and weekends”. It cut down what Hatch agents could reach and limited the ports and addresses the agents’ host machines could connect to. “With Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm,” it said.\n\n## “Half-baked protections”\n\nThe Meta source, who spoke to 404 Media on condition of anonymity, said teams were asked to push hot fixes as fast as possible without delaying the launch, leading to “half-baked protections being rushed out to enable the launch”. The source added: “Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch.”\n\nA last-minute security push is not unusual before a big launch, as 404 Media notes. Meta’s own rules show how seriously it rates this kind of bug: its [Muse bug bounty page](https://bugbounty.meta.com/payout-guidelines/muse/) pays up to $300,000 for “reaching Meta production services or internal networks from Muse”, its highest category, and up to $250,000 for breaking into other users’ virtual machines.\n\nMeta told 404 Media that Muse is “the first personal AI agent built for everyone” and that it is proud of its work to make it “safe, secure and private”. The company said it had strengthened Muse “through extensive dogfooding, agentic red teaming and our bug bounty program”, and said that work continues. Meta did not say whether any of the flaws were exploited.\n\n## “One KVM escape away”\n\nMuse has had a bumpy first month. Patrick Wardle, the macOS researcher who recently [found a flaw in ChatGPT’s Mac app](https://madrobot.blog/2026/10/02/chatgpt-mac-app-flaw-patched-patrick-wardle-objective-see-chat-logs/), [warned on September 21](https://x.com/patrickwardle/status/2102045926474785265) that a zero-day in Muse let other apps and terminal commands take control of it. One user’s agent [sold his keyboard and gave a stranger his address](https://madrobot.blog/2026/09/28/meta-muse-ai-agent-shared-home-address-facebook-marketplace/), and 404 Media says another got Muse to export his Instagram followers and their followers, which Meta’s security teams looked into.\n\nPlease don't install - it's trivial to turn Muse into the ultimate backdoor 💀👀\n\nYa, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. \n\nBut serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.\n\nLet me show you. 🧵\n\n[September 21, 2026](https://x.com/patrickwardle/status/2102045926474785265)\n\nWardle told 404 Media the design itself is the problem, because users have full control inside a machine that sits in Meta’s production network:\n\nHaving access to production environment literally one KVM escape away, is plain irresponsible.\n\nPatrick Wardle, security researcher\n\nHe added that AI is lowering the cost of finding and exploiting “exactly these kinds of complex virtualization vulnerabilities”.\n\n## Why it matters\n\nMuse is sold on doing things for you with full access to your accounts, which is exactly what makes a hole in its walls so dangerous. The report comes as AI agents from OpenAI and others are already [breaking into systems they were never meant to touch](https://madrobot.blog/2026/09/26/openai-agents-hugging-face-hack-loot-slack-swarm-traces-report/), and as Meta’s own engineers, by the source’s account, expect a breach. Anyone weighing [whether to trust Muse](https://madrobot.blog/2026/09/25/what-is-meta-muse-ai-agent-explained/) now has one more thing to consider.\n\n*Sources: [404 Media](https://www.404media.co/meta-rushed-to-fix-muse-vm-escape-vulnerability-immediately-before-launch/); [Meta Bug Bounty: Muse payout guidelines](https://bugbounty.meta.com/payout-guidelines/muse/); [Patrick Wardle on X](https://x.com/patrickwardle/status/2102045926474785265).*", "url": "https://wpnews.pro/news/meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal", "canonical_source": "https://madrobot.blog/2026/10/05/meta-muse-vm-escape-vulnerability-rushed-fix-before-launch/", "published_at": "2026-10-05 15:08:00+00:00", "updated_at": "2026-10-05 15:20:34.667167+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["Meta", "Muse", "Hatch", "Mark Zuckerberg", "Surupa Biswas", "Francois Richard", "Josh Barry", "404 Media"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal", "markdown": "https://wpnews.pro/news/meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal.md", "text": "https://wpnews.pro/news/meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal.txt", "jsonld": "https://wpnews.pro/news/meta-rushed-to-fix-muse-flaws-that-could-have-let-users-break-into-its-internal.jsonld"}}