Meta fixed Muse security flaws days before launch after KVM escapes surged
404 Media reports that Meta engineers found several vulnerabilities in Muse’s virtual machines before launch, including one that could have let an ordinary user reach sensitive internal databases and services. Internal posts described a multi-team hardening push, while an anonymous Meta source told 404 Media that fixes were rushed to avoid delaying the release. The report matters because Muse can act on users’ accounts from infrastructure connected to Meta’s production systems.
Bottom line — Meta offers up to €276,000 ($300,000) for a Muse flaw that reaches its production services or internal networks.
Go deeper 6
-
404 Media says the issues reached Mark Zuckerberg and that security teams worked nights and weekends before launch.
-
An internal post dated 18 September said the hardening push began on 27 August and involved limiting what Muse agents and their host machines could reach, according to 404 Media.
-
404 Media reports that at least one flaw was linked to an exploit in Linux’s KVM code disclosed in July.
-
Meta told 404 Media that it had used extensive internal testing, agentic red-teaming and its bug-bounty programme, and that security work continues.
-
Security researcher Patrick Wardle told 404 Media that placing user-controlled code near production services makes the virtualisation boundary a production-security boundary.
-
404 Media also reported a separate post-launch flaw in Muse’s macOS app and an investigation into an agent exporting Instagram followers and their followers.