According to internal documents and a Meta source cited by 404 Media, Meta engineers discovered several security vulnerabilities in Muse, its AI agent product, in the weeks before launch. At least one of these flaws was a KVM escape that could have allowed a normal user to break out of Muse's virtual machine and reach sensitive internal Meta databases and services. The issues were considered serious enough that they were escalated to Mark Zuckerberg.

Meta's internal infrastructure team acknowledged the scramble in a September 18 post, saying a "sudden spike in reported KVM escapes" prompted a service hardening push that started on August 27 and lasted several weeks. Muse launched just 11 days after that push began. A Meta source told 404 Media that security teams were asked to push hot fixes quickly so the launch wouldn't be delayed, resulting in what the source described as "half-baked protections being rushed out."

The source also said many senior engineers believe a massive data breach is inevitable as a result of Muse, which is called "Hatch" internally. Since launch, security researcher Patrick Wardle found a zero-day that allowed apps and terminal commands to control a user's Muse, and another user was able to export Instagram followers in ways that should not have been possible. Meta's bug bounty program lists VM escapes as its highest-risk category, offering up to $300,000 for such findings. A Meta spokesperson defended the company's security work, citing red teaming and its bug bounty program, but the pre-launch rush and post-launch issues raise questions about whether the{