On August 27, 2026, eleven days before Meta released its AI agent Muse to the public, a hardening effort began inside the company’s infrastructure organisation. 404 Media gives that date, citing internal documents and an anonymous source. Muse launched on September 8. In the days between, by the outlet’s account, several security teams worked nights and weekends, and at least one flaw was serious enough to be taken all the way up to Mark Zuckerberg.
Here is one way to think about it. Every power that grows large enough eventually lets strangers inside its walls. You can judge how much it trusts those strangers, and itself, by the rooms it builds for them and the thickness of the partitions between the guest quarters and the treasury.
The room and the wall
Each Muse instance, 404 Media reported, runs in its own kernel-based virtual machine, or KVM. The machine is wired to Meta’s critical infrastructure but is supposed to stay sealed off from it. An escape is what the word suggests: a flaw that lets whoever is inside break out and reach the system hosting it, or other users’ machines. On the far side of that wall, Gadget Review notes, are Meta’s production services and the outside accounts each user has authorised the agent to act on. A breach would not stay inside one person’s session.
According to 404 Media, an internal post dated September 18 described a multi-team “mad dash” to deal with “a sudden spike in reported KVM escapes.” It was attributed to three Core Infrastructure leaders: Surupa Biswas, vice president of core infrastructure; Francois Richard, vice president of engineering; and Josh Barry, senior director of engineering. They said plainly what was new:
“With Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm.”
Several of the flaws, the outlet reported, were in the Linux virtualization software Meta uses for Muse. At least one was related to an exploit found in Linux KVM code in July. The repairs involved shrinking the network surface open to Muse agents and limiting which destinations could be reached from inside the virtual machines.
Meta has not publicly confirmed this picture of urgency. Its public position, as Gadget Review summarised it, is that it carried out extensive security testing and is still hardening the product.
The price of a door
One figure comes from Meta itself. Its bug-bounty programme puts a breach of the boundary between Muse and production in its highest-impact category and pays up to $300,000 for a qualifying report. A bounty works as a kind of inventory: the size of the reward shows what the owner is most afraid of losing.
Patrick Wardle, a security researcher, told 404 Media that the problem lay in the design: “A single failure in KVM (or even a vulnerability or misconfiguration in an internally reachable service) can therefore turn arbitrary user code into production access.” He called building it this way “plain irresponsible.” This is an expert’s judgement about risk. No breach of production has been reported.
After the launch
Wardle also looked at the client software. Meta released the Mac app for Muse on September 17. On September 21, the Eastern Herald reported, he disclosed a zero-day in it, with a working proof of concept he called “not-a-mused.” An undocumented setting, endo_voyager_dictation_endpoint, could be changed by any process running under the user’s account. That would send Muse’s dictation to a server of the attacker’s choosing, potentially exposing audio, prompts and authentication material.
Meta shipped a hotfix shortly after midnight, about 16 hours after the disclosure, according to the Eastern Herald. Wardle confirmed it on X: “Hooray, hot-fixed!” David Singleton of Meta Superintelligence Labs described the bug as a local privilege-escalation issue that required malicious code to be running under the user’s account already, The Verge reported. The two sides disagreed about how exploitable it was in practice. The question was whether a remote social-engineering trick of the ClickFix kind could realistically give an attacker that foothold, a scenario TechRadar also covered.
Then there were the followers. According to 404 Media, one Muse user got the agent to export his Instagram follower list, along with his followers’ followers. The agent reportedly should not have been able to do this, and Meta’s security teams investigated. It happened in the same weeks that Amazon moved to block the agent from its store, and after earlier reports that Muse would zip up its own filesystem on request.
Guests in the house
The three executives were right that the arrangement is new. A platform company has long held its users’ data. Now it hosts their agents too, running code that users steer inside rooms built next to its own machinery. Gadget Review points out that users may have considerable control inside those virtual machines, so the wall around them stops being a sandbox for one app and becomes the outer wall of production itself. Researchers had already warned that the web was not ready for a free agent at this scale.
The record gives the dates in order. An exploit in Linux KVM code was found in July. The scramble began on August 27. Muse launched on September 8, the executives’ post went out on September 18, and the Mac zero-day was disclosed on September 21 and patched the next day.
Meta has also mentioned a Muse Confidential VM, meant to keep even Meta itself out of the data in users’ virtual machines. VentureBeat reported that its timing and implementation details remain unconfirmed.

