404media.co web signal

Meta scrambled to patch Muse KVM-escape bugs before launch

TL;DR

  • Meta engineers found KVM escape vulnerabilities in Muse that could have reached internal databases, triggering a hardening push on August 27 before the September 8 launch.
  • The issues reached Mark Zuckerberg; Meta's bug bounty now pays up to $300,000 for a Muse VM escape, with several flaws tied to Linux virtualization software.
  • Researcher Patrick Wardle called the design 'plain irresponsible,' arguing a single KVM failure can turn arbitrary user code into Meta production access.

Meta engineers found at least one KVM escape in Muse, the company's new personal AI agent, in the weeks before its September 8 launch, 404 Media reports. A successful exploit would have let a user break out of their isolated virtual machine and reach Meta's own internal databases. The problem escalated to Mark Zuckerberg and triggered a hardening push that began on August 27, roughly 11 days before launch.

In an internal September 18 post, Meta's Surupa Biswas, Francois Richard and Josh Barry wrote that "with Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm," and that "a sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push." Meta's bug bounty now pays up to $300,000 for a VM escape in Muse. Several of the flaws were in the underlying Linux virtualization software Meta uses, with at least one tied to a Linux kernel bug exploited publicly in July.

Security researcher Patrick Wardle, who later disclosed a post-launch zero-day affecting Muse's macOS client, was blunt about the architecture, calling it "plain irresponsible" to have production "literally one KVM escape away" from end-user agents. He added that "a single failure in KVM (or even a vulnerability or misconfiguration in an internally reachable service) can therefore turn arbitrary user code into production access."

The piece moved fast through the agent-security crowd; four of the researchers on our Who's Who tracker posted it the day it went up.

404 Media also reports a post-launch incident in which a user got the agent to export Instagram follower data beyond what the account was authorized to pull.

Shared on Bluesky by 4 AI experts