Meta engineers discovered several security vulnerabilities in the company viral AI agent product Muse during the weeks leading up to its launch. At least one of these flaws could have allowed malicious users to break outside of the intended environment and access Meta own sensitive databases and services. The issues were severe enough to reach Mark Zuckerberg and prompted staff to work overtime to fix them.
Engineers worked nights and weekends to patch bugs
The specific vulnerabilities required a multi-team mad dash to fix a sudden spike in reported kernel-based virtual machine escapes according to an internal post by Meta executives. Muse runs each individual instance on a kernel-based virtual machine that is supposed to be isolated from Meta critical infrastructure. A virtual machine escape occurs when a security vulnerability allows an instance to escape that environment and interact with the system running it or other users virtual machines.
According to a Meta source, internal security documentation, and internal posts viewed by 404 Media, at least one flaw allowed an outside attacker or normal Muse user to access data in sensitive internal Meta databases. At least one vulnerability related to an exploit found in Linux kernel-based virtual machine code in July. Several issues resided in the underlying Linux virtualization software that Meta uses for Muse.
Executives acknowledged the security push in a post
The security issue was raised to Mark Zuckerberg, and several security teams worked nights and weekends in the leadup to launch to fix the problems. A Meta source stated that security teams were asked to push hot fixes as quickly as possible without delaying the launch, leading to half-baked protections. Many senior engineers believe a massive data breach is inevitable as a result of Hatch, which is Muse internal codebase name.

This security push was acknowledged in an internal post made on September 18 by Meta vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard, and senior director of engineering Josh Barry. The executives told the core infrastructure team that hosting and running agents on behalf of end users represents a fundamentally different paradigm. The post noted the hardening push started on August 27 and lasted a handful of weeks and weekends.
Bug bounty program lists high payouts for escapes
A virtual machine escape of Muse is classified as a serious security issue in Meta bug bounty program. The company offers a payment of $300,000 to security researchers who find a bug allowing for a virtual machine escape, which is its highest listed payout. The highest level of risk involves reaching Meta production services or internal networks from Muse.
A Meta spokesperson stated that Muse is the first personal AI agent built for everyone and that the company is proud of the work done to make it safe, secure, and private. The rollout has been uneven with security researcher Patrick Wardle finding a zero-day allowing apps and terminal commands to control a user Muse. Another user managed to get Muse to export Instagram followers, prompting an investigation by Meta security teams.
Wardle noted that Hatch makes the virtualization boundary a production security boundary. He added that a single failure in kernel-based virtual machines can turn arbitrary user code into production access. The next known step is the ongoing security work and bug bounty program management by Meta.



