Majorsafety alignmentMeta

Meta Addresses VM Escape Vulnerability in Muse AI Agent Before Launch

Published
Oct 5, 2026 — 14:13 UTC

On September 8, Meta launched its Muse AI agent after a security push initiated on August 27 to address a critical VM escape vulnerability. This vulnerability was identified in the Linux kernel-based virtual machine code in July, prompting Meta's leadership, including CEO Mark Zuckerberg and VP of Core Infrastructure Surupa Biswas, to prioritize security measures. The internal acknowledgment of the security push came on September 18, just ten days after the launch, indicating the urgency of the situation. The push lasted several weeks and was driven by a sudden increase in reported KVM escapes and growing concerns over agentic safety issues, as stated by Biswas, VP of Engineering Francois Richard, and Senior Director of Engineering Josh Barry. Security researcher Patrick Wardle highlighted the risks associated with the design of the Muse agent, noting that it effectively makes the virtualization boundary a production security boundary, which he deemed 'plain irresponsible.' Meta's bug bounty program offers up to $300,000 for vulnerabilities allowing VM escape, reflecting the seriousness of the issue. This incident underscores the ongoing challenges in securing AI systems as they become more complex and integrated into production environments.

Summarised from 404 Media's original report by the Turing Wire Newsdesk. Read the original for the full story.

Source: 404 Media