Meta engineers identified multiple security flaws in the Muse AI agent weeks before its release, including one capable of allowing attackers to breach the virtual machine environment and access Meta’s internal databases. The issues were severe enough to reach Mark Zuckerberg, prompting staff to work overtime to resolve them.
In this article
The rush to fix KVM escapes
Internal posts by Meta executives to the core infrastructure team describe the period as a “mad dash” following a sudden spike in reported KVM escapes. Muse runs on a kernel-based virtual machine that connects to a user’s accounts but must remain isolated from Meta’s critical infrastructure. A KVM escape occurs when a flaw allows the virtual machine to interact with the host system or other users’ machines.
How the flaws could have worked
At least one vulnerability was linked to an exploit discovered in Linux kernel-based virtual machine code in July. Sources told 404 Media that a normal Muse user could have used this flaw to access sensitive internal Meta data. Meta granted anonymity to the source to discuss these security matters. The vulnerabilities were located in the underlying Linux virtualization software.
Internal warnings about the launch
Security teams received instructions to push hot fixes quickly without delaying the launch, according to a Meta source. This approach led to “half-baked protections being rushed out.” Several senior engineers believe a massive data breach is inevitable as a result. Muse is known internally as “Hatch.”
On September 18, ten days after Muse launched, Meta’s vice president of core infrastructure Surupa Biswas, vice president of engineering Francois Richard, and senior director of engineering Josh Barry sent an internal post to the core infrastructure team. They noted that hosting agents on behalf of end users represented a fundamentally different paradigm. The teams rallied for a service hardening push to address the spike in KVM escapes and heightened awareness of agentic safety issues.
The work began on August 27 and lasted a handful of weeks and weekends, yet Muse released just 11 days later. Steps included reducing the surface area accessible to Hatch agents and constraining the port and IP destinations the hosts could reach.
Payouts and risks
Meta classifies a virtual machine escape as a serious security issue. The company offers $300,000 for a bug that allows a VM escape, the highest payout on its bug bounty website. Muse lets users create a personalised AI agent that runs in a dedicated per-user virtual machine and connects to email, calendar, messaging, browsing, and third-party accounts. Compromising that boundary is treated as a first-class security risk.
Post-launch findings
Muse has been popular for cancelling subscriptions, making restaurant reservations, and booking travel. However, security researcher Patrick Wardle found a zero-day vulnerability allowing apps and terminal commands to control a user’s Muse. Another user successfully had the agent export their Instagram followers and the followers of those followers, actions Meta’s security teams investigated.
Wardle told 404 Media that Hatch makes the virtualization boundary a production security boundary. Users hold root privileges inside a VM placed within Meta’s production environment with limited access to internal services. A single failure in KVM or a vulnerability in an internally reachable service can turn arbitrary user code into production access. Wardle described the design as inherently risky, noting that AI lowers the cost of finding and exploiting complex virtualization vulnerabilities. He added that having access to the production environment one KVM escape away is plain irresponsible.
In a statement to 404 Media, a Meta spokesperson said Muse is the first personal AI agent built for everyone. They expressed pride in the work to make it safe, secure and private with built-in protections and user controls. The company cited extensive dogfooding, agentic red teaming and the bug bounty program as part of the effort, noting that the work continues.




