← All updates

Muse · News date: · WATCH

Type: Personal Assistant

Meta rushed to fix Muse VM escapes before launch

Your move: Bug bounty still pays up to $300,000 for a VM escape

On October 5, 2026, 404 Media reported that Meta found security flaws in Muse in the weeks before launch, including at least one that could have let a normal user break an agent out of its isolated virtual machine and reach Meta's internal databases and services. The issues were raised to Mark Zuckerberg, and an internal post said a hardening push started on August 27, 2026, with teams working nights and weekends so the launch would not slip.

Why it matters

The work was done so Muse could launch on time, so there is no patch for current users to install. A Meta source told 404 Media the protections were rushed, with "half-baked protections" shipped to keep the date. Security researcher Patrick Wardle said leaving Meta's production systems one virtual-machine escape away is "plain irresponsible." Meta's bug bounty still pays up to $300,000 for a VM escape that reaches those systems.

Source: 404 Media ↗

Published by Agent Log. The summary reports the linked source; “Why it matters” and the verdict are Agent Log's interpretation.

More Muse updates →