Weeks before Meta launched its AI agent Muse, engineers discovered security vulnerabilities that could have allowed users to break out of the product's virtual-machine sandbox and reach Meta's own sensitive infrastructure, according to internal documents and a source cited by 404 Media.

Muse instances run on kernel-based virtual machines meant to be isolated from Meta's critical systems. A KVM escape would let a malicious instance interact with the host or other users' VMs. 404 Media reported that at least one flaw could have let an ordinary Muse user access data in sensitive internal Meta databases, and that at least one was tied to a Linux kernel VM exploit from July.

The issues were severe enough to reach CEO Mark Zuckerberg, and staff worked overtime to fix them. Meta executives described a multi-team "mad dash" to address a sudden spike in reported KVM escapes before launch. The report does not say whether any user exploited the vulnerabilities.