Wednesday, Oct 7 | --:--
Back to home

404 Media: Meta Rushed Muse KVM-Escape Fixes Before Launch — No Known Exploitation

404 Media reports that in the weeks before Muse's Sept. 8 launch, Meta engineers found several security vulnerabilities in the personal agent; at least one could have allowed an ordinary user to break out of the agent's KVM and reach internal Meta databases. A Meta source called the hot fixes 'half-baked.' There is no known exploitation. This is a single-source flagged report — not a breach — and it is a different incident from the earlier Muse Spark cyber-eval leak.

Times of AI Desk 5 min read Menlo Park, CA View as Markdown
Cover illustration for 404 Media: Meta Rushed Muse KVM-Escape Fixes Before Launch — No Known Exploitation

Muse puts each user's agent — holding that user's email, calendar and accounts — one hypervisor bug away from Meta's production network. A single-outlet report says Meta treated that risk as a launch-deadline fix.

404 Media reported on October 5 that in the weeks before Muse's September 8 launch, Meta engineers found several security vulnerabilities in the personal-agent product. According to a Meta source and internal documents seen by 404 Media, at least one could have allowed an ordinary Muse user to break out of the agent's kernel-based virtual machine and reach sensitive internal Meta databases and services.

There is no known exploitation.

What 404 Media says happened

An internal September 18 post by core-infrastructure leaders Surupa Biswas, Francois Richard and Josh Barry, quoted by 404 Media, describes "a sudden spike in reported KVM escapes" and a hardening push that began August 27. That push reduced the surface area reachable by Muse agents (codenamed "Hatch") and constrained the ports and IPs they can reach. Some flaws were in the underlying Linux virtualisation software; one was tied to a KVM exploit found in July. The issue reached Mark Zuckerberg, according to the report.

The Meta source said security teams were pushed to ship hot fixes without delaying launch, calling them "half-baked protections," and said many senior engineers believe a massive data breach is inevitable. Meta's bug-bounty page lists a VM escape into Meta production as its top-risk category, with up to $300,000 in payouts.

Meta's statement says Muse was strengthened through dogfooding, agentic red-teaming and its bug bounty — neither confirming nor denying the specifics. Researcher Patrick Wardle, who earlier found a Muse zero-day, told 404 Media the design makes "the virtualization boundary a production security boundary."

A different Muse security thread

This report is separate from the August Muse Spark cyber-eval incident, which concerned evaluation leakage rather than hypervisor isolation. Today's Personal Agent Protocol announcement — and Meta's claim via CNBC that Muse has millions of US users — is why the isolation design matters now.

Limits

  • Single source: one anonymous Meta source plus internal posts seen by 404 Media. Follow-ups are rewrites, not corroboration.
  • No known exploitation. Flagged report, not a confirmed breach.
  • Meta's statement neither confirms nor denies the specifics.
  • CNBC supports only Muse user-count context, not the vulnerability claims.

Sources

Prior Coverage

Earlier Times of AI reporting on this thread.

Scroll to continue reading