Security1 publisher2 min readPublished
Meta rushed fixes for KVM escapes into its Muse AI agent before launch
Meta began fixing KVM escapes in its Muse AI agent on August 27, 11 days before launch, an internal post seen by 404 Media shows. Each agent's VM holds its owner's email and account access, so a break-out would reach other users and Meta's own systems.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- At least one flaw could have let an ordinary Muse user reach data in sensitive internal Meta databases, according to a Meta source and internal documents seen by 404 Media.
- Several of the vulnerabilities were in the underlying Linux virtualization software that Meta uses to run Muse.
- The problem was raised to Mark Zuckerberg, and several security teams worked nights and weekends ahead of launch.
- Executives Surupa Biswas, Francois Richard and Josh Barry acknowledged the push in a September 18 post to core infrastructure staff, 10 days after launch.
- Meta's bug bounty offers $300,000 for a Muse VM escape, the highest payout listed on its site.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Meta's threat model starts with a customer: anyone who can run a Muse agent is in position to try an escape that lands beside other users' email and account access.
- decision Users connecting email, calendar and third-party accounts to Muse are trusting a boundary that, on the executives' own timeline, was still being hardened after launch.
- constraint With several bugs in the Linux virtualization layer, Muse's isolation is only as current as Meta's KVM patching, separate from anything in the agent's own code.
- contradiction Executives call it a service hardening push while a Meta source calls the protections half-baked, and the public record cannot yet settle whether escape paths were closed or only narrowed.
Meta's bug bounty page spells out what sits behind the boundary. Each agent "runs in a dedicated per-user virtual machine and connects to that user's own services: email, calendar, messaging, browsing, and third-party accounts," the page says [15]. That VM also connects to Meta's critical infrastructure and is supposed to be isolated from it [3]. In a KVM escape, code in one Muse instance reaches the host that runs it, or other users' VMs [4]. The program's top risk tier is "Compromise of Meta production and users beyond Muse" [16].
Work began on August 27 [12]. Muse shipped 11 days later [12]. By the executives' account the push ran over several weeks and weekends [12], so part of it ran after customers were already using the product [17]. "A sudden spike in reported KVM escapes, plus heightened awareness of agentic safety issues made us rally on a service hardening push," they wrote [11].
Two fixes are named. Teams worked to "reduce the surface area accessible to Hatch agents" and to "constrain port/IP destinations Hatch and VMVM hosts can reach" (Hatch is Meta's internal name for Muse) [13][9]. Cutting surface area shrinks what a guest can attack. Egress limits work on the host side, bounding where code that has already left a VM can connect [13].
A Meta source who spoke to 404 Media described those weeks differently. The source said they felt security teams were asked to push hot fixes as quickly as possible and without delaying launch [20]. The outcome, the source said, was "half-baked protections being rushed out to enable the launch. Many senior engineers believe it's inevitable we're going to have a massive data breach as a result of Hatch" [19].
Only the bounty page is public [15]. The rest of the report rests on internal posts and documents 404 Media viewed and on one source it granted anonymity [2][18].
The bugs were found before launch [1], and at least one was related to an exploit found in Linux KVM code in July [5]. The report does not name a CVE or describe any attacker using these flaws against Muse users. When the next flaw turns up in that code, Muse hosts carry it until patched [5]. The port and IP limits on Hatch and VMVM hosts then decide how far an escape gets [13]. Outside researchers have found several other security issues in Muse since launch, 404 Media reported [8].
What to watch
- Identification of the July Linux KVM exploit tied to Muse by CVE, so other KVM operators can check their own hosts.
- Any payout or public disclosure under Meta's $300,000 Muse VM escape bounty tier.
- Details of the security issues outside researchers have found since launch, and whether any reach past the agent's VM.