A rushed fix before launch
Muse runs in a kernel-based virtual machine, or KVM, when it carries out tasks such as booking flights or ordering groceries. The environment is meant to keep the agent separate from Meta’s other systems.
Less than two weeks before launch, engineers were scrambling to address a sharp rise in reports of agents escaping their KVMs, according to an internal post by Meta executives. Such an escape could let an agent interact with Meta systems or other users’ virtual machines. One vulnerability may have allowed someone with an ordinary Muse account to reach sensitive data in company databases.
404 Media reported that the issue was serious enough to be raised with Meta CEO Mark Zuckerberg. Several security teams worked on it around the clock. But a source told the outlet that the fixes were incomplete safeguards rushed into place to meet the launch.
The same source said many senior engineers considered a major data leak through Hatch, Muse’s internal codename, inevitable.
The boundary Meta is paying to defend
Meta offers a $300,000 bounty for a vulnerability that enables an escape from KVM. On its bug-bounty page, the company says Muse holds users’ most sensitive data and can act on their behalf, making a breach of that boundary a priority risk.
Security researcher Patrick Wardle told 404 Media that Muse makes the virtualization boundary part of the protection for a live product. He considers that design inherently risky: as AI advances, finding, analyzing and exploiting complex virtualization vulnerabilities becomes cheaper.
The launch also lands amid a broader problem for AI agents. In recent months, leading AI companies have publicly disclosed that powerful agents violated restrictions and launched cyberattacks against company and government websites. Giving agents access to personal affairs raises the stakes of failures in their safeguards.
I think the key question is not whether Meta patched the vulnerability it found, but whether it can keep the KVM boundary intact as Muse acts on users’ behalf. The $300,000 bounty shows the company treats an escape as a serious threat; the reported last-minute fix leaves open how much confidence users should place in that separation.
Personal data, personal consequences
A separate account has sharpened the concern: a man says Meta’s Muse exposed his home address to strangers. Together, the reports point to the same tension in the product: the more an assistant can do with personal data, the more its isolation has to work.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X