According to internal documents and an anonymous source cited by 404 Media, Meta engineers identified multiple vulnerabilities in Muse’s virtualization boundary during those final weeks. At least one was serious enough to reach Mark Zuckerberg, according to the same report.
A KVM escape is worth understanding before you dismiss it as enterprise plumbing. Think of Muse’s virtual machine as your apartment: contained, yours, separated from everything else in the building. A KVM escape is finding a door in your apartment wall that opens directly into the building’s utility core, where the electrical panels, water mains, and master keys live.
In Muse’s case, that utility core connects to Meta’s production services and the services you authorized the agent to access on your behalf. A breach there is not a bug confined to your session; it is a production-security problem.
A September 18 internal post, reported by 404 Media and attributed to Core Infrastructure executives Surupa Biswas, Francois Richard, and Josh Barry, put the stakes plainly: “With Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm.”
The same report says teams worked nights and weekends, and that the hardening effort involved reducing the network surface available to Muse agents and restricting the destinations reachable from within the virtual machines. Those allegations come from an anonymous source and internal documents; Meta has not confirmed that urgency framing in any public statement, saying only that it conducted extensive security testing and continues to harden the product.
One number speaks without editorializing. Meta’s own bug-bounty program classifies a breach of the Muse-to-production boundary as its highest-impact category, offering rewards of up to $300,000 for qualifying reports.
One Vulnerability Was Not Enough
Post-launch disclosures showed that the pre-launch fixes addressed only part of the picture.
After Muse shipped, security researcher Patrick Wardle disclosed a zero-day in the macOS application. An undocumented configuration setting let a local process redirect Muse’s dictation endpoint to an attacker-controlled server, potentially exposing audio, prompts, and authentication material.
Meta issued a hotfix and characterized the flaw as a local privilege-escalation issue, one requiring malicious code already running under the user’s account. David Singleton of Meta Superintelligence Labs said as much publicly, as reported by The Verge. Wardle and Meta disagreed on how practically exploitable the issue was, with the dispute centered on whether a remote social-engineering attack could realistically deliver the required local access.
Wardle’s broader concern, as reported by 404 Media, cuts to the structural problem: “A single failure in KVM (or even a vulnerability or misconfiguration in an internally reachable service) can therefore turn arbitrary user code into production access.”
That is expert risk assessment, not a confirmed account of a production breach. Separately, 404 Media reported that a Muse user caused the agent to export an Instagram follower list, including followers of followers, an action that reportedly should not have been permitted and that Meta’s security teams investigated.
Handing an AI agent the keys to your accounts and then discovering the lock was still being fitted is less like beta-testing software and more like handing a valet your car before the brakes have been inspected.
The Standard the Industry Needs to Set
The question is not whether Meta should have shipped; it is what “ready” should mean for agents with this level of access.
Agentic AI sits at an uncomfortable intersection. User-controlled code runs inside cloud infrastructure adjacent to production services, and users may have substantial control inside the VM. That elevates the virtualization boundary from an application sandbox to a production-security perimeter.
Meta has referenced plans for a Muse Confidential VM designed to prevent even Meta from accessing user-VM data. Timing and implementation details remain unconfirmed, according to VentureBeat.
The convenience Muse promises is genuinely worth pursuing. But convenience built on a security model that was still hardening at launch is a standard the whole industry should be held to, starting now, before the next launch clock runs out.




























