DigestAI news desk

Cut through the AI noise.

Society & Work5 min read

Meta rushed to fix Muse VM escape flaws before launch, report says

404 Media reports that Meta engineers discovered several severe security vulnerabilities in its AI agent product, Muse, in the weeks leading up to its launch. At least one of these flaws, related to Linux kernel-based virtual machine code, could have allowed malicious users to escape their isolated environment and access Meta’s sensitive internal databases. The issues were significant enough to…

1 source

Key points

  • Meta fixed severe VM escape vulnerabilities in Muse just 11 days before launch.
  • At least one flaw could have allowed attackers to access Meta's internal databases.
  • Security researcher Patrick Wardle found a zero-day bug in Muse after its release.

According to internal posts and a Meta source, the security push began on August 27, just 11 days before Muse’s release. Executives described a "sudden spike in reported KVM escapes" that required a "mad dash" to harden the service. The source claimed that security teams were pressured to deploy "half-baked protections" to avoid delaying the launch, with some senior engineers fearing a massive data breach as a result.

Since launch, security researcher Patrick Wardle identified a zero-day vulnerability that allowed apps to control a user’s Muse, while another user successfully exported Instagram follower data that should have been inaccessible. Meta stated that it treats the compromise of the virtual machine boundary as a first-class security risk and offers a $300,000 bounty for such bugs. The company maintains that Muse is secure due to extensive testing and user controls, though the uneven rollout and post-launch discoveries suggest ongoing challenges in securing agentic AI systems.

Model page: Muse →

The story so far

2 episodes →
  1. Meta rushed to fix Muse VM escape flaws before launch, report saysthis story
Full story from 404media.co · by Jason Koebler · via Mastodon trending linksOpen source ↗

Meta Rushed to Fix Muse 'VM Escape' Vulnerability Immediately Before Launch

404media.co · 5 October 2026

Loading the full article…

This text was published by 404media.co and written by Jason Koebler. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗

Topics · follow one to build your own front page
Meta404 MediaMuseMark ZuckerbergPatrick WardleSurupa BiswasFrancois RichardJosh Barry

The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us. Published by Martin K., who runs Digest AI and handles corrections.

Comments

via GitHub Discussions

More in Society & Work

All →

Related stories