Meta Rushed to Fix Muse ‘VM Escape' Vulnerability Soon Before Launch
The vulnerability could have let a Muse user access sensitive internal Meta databases.
Meta experienced an intense effort to resolve several critical security vulnerabilities in its new AI agent product, Muse, immediately before its scheduled launch. At least one of these vulnerabilities could have allowed malicious users to breach Muse's intended environment and gain access to sensitive internal databases and services.
The issues surfaced shortly before Muse's launch and required a rapid response from Meta's engineering teams. "KVM escape" incidents, where an AI agent could break out of its virtual machine, were a significant concern. These exploits were traced back to a July exploit in the Linux kernel-based virtual machine code. The company considered the vulnerabilities severe enough to inform Mark Zuckerberg, prompting a series of emergency fix efforts.
Meta's internal post acknowledged the intense work of securing the product in the final weeks. The vulnerabilities highlight the heightened risks associated with agentic AI systems and the need for robust security measures, especially as other companies face similar challenges following their launches.
Written by urgent.news from 404 Media's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.