Meta Rushed to Fix Muse 'VM Escape' Vulnerability Soon Before Launch
8 hours ago
- Meta engineers discovered several security vulnerabilities in Muse, an AI agent product, before its launch, including at least one that could allow malicious users to access Meta's sensitive databases.
- The vulnerabilities were severe enough to escalate to Mark Zuckerberg, requiring a multi-team 'mad dash' with overtime work to fix 'a sudden spike in reported KVM escapes'.
- Muse runs each instance on a kernel-based virtual machine (KVM) isolated from Meta's infrastructure, but a KVM escape vulnerability could break that isolation and compromise production systems.
- At least one vulnerability exploited a Linux KVM bug from July, and Meta offered up to $300,000 in bug bounties for such VM escapes.
- The security push was acknowledged in an internal post by Meta executives, who noted the work involved reducing the attack surface and constraining agent network access.
- A Meta source described the fixes as 'half-baked protections rushed out to enable the launch,' leading to fears of a major data breach, while security researcher Patrick Wardle called the design 'inherently risky' and 'plain irresponsible.'
- Since launch, Muse has had additional issues, including a zero-day exploit and a user exporting Instagram followers beyond intended limits.
- Meta responded that Muse is designed with safety, security, and privacy protections, and they continue to strengthen it through red teaming and bug bounty programs.