Meta’s Muse AI agent faced security scare before launch; engineers feared ‘massive data breach’

Edited By: Anand P
Meta Muse
Meta Muse

Meta’s new Muse AI agent was barely weeks away from launch when engineers discovered a security vulnerability that could have allowed users to break out of the virtual machines running the agent and potentially access sensitive data stored in Meta’s internal systems, according to a report by 404 Media.

The vulnerability raised concerns inside Meta over whether the safeguards surrounding Muse were strong enough to protect the vast amount of personal information the AI agent is designed to handle.

Muse is Meta’s AI-powered personal assistant, built to perform tasks on a user’s behalf rather than simply respond to prompts. The agent can interact with a computer to carry out actions such as booking flights, shopping for groceries and managing other tasks. The technology is designed to operate with access to sensitive user information, including emails and financial accounts, making security around the system particularly critical.

To perform such computer-based tasks, Muse agents run inside a kernel-based virtual machine, or KVM. The virtual environment is intended to isolate an AI agent from Meta’s wider infrastructure and prevent it from accessing other systems or users.

Also read | Meta’s new AI ‘Muse’ can manage your accounts, but Sentinel needs your OK for every purchase

However, engineers reportedly detected a “sudden spike in reported KVM escapes” less than two weeks before Muse was launched. A KVM escape occurs when software running inside a virtual machine breaks through the isolation layer and gains access to the underlying host system or other environments.

According to 404 Media, one of the vulnerabilities could have allowed someone using an ordinary Muse account to gain access to sensitive information held in Meta databases.

The seriousness of the issue reportedly triggered an emergency effort within Meta, with several security teams working around the clock to address the problem. The issue also reached CEO Mark Zuckerberg, according to the report.

The vulnerability was eventually fixed in what 404 Media described as a “mad dash” ahead of the launch. But the report also cited concerns among some Meta employees that the measures introduced under the pressure of the launch may not have been sufficient.

Also read | WhatsApp Business changes from October 1: What is free, what is paid and how much?

“Many senior engineers believe it’s inevitable we’re going to have a massive data breach as a result of Hatch,” a Meta source told 404 Media, referring to Muse by its internal nickname.

The source also questioned the robustness of the protections introduced before launch, describing them as “half-baked protections being rushed out to enable the launch.”

The stakes are particularly high because Muse is designed to act with a degree of autonomy. Unlike a conventional chatbot that primarily generates text or answers questions, an AI agent can use software, navigate websites and perform actions on a user’s behalf.

That means a security failure could potentially give an attacker access not only to information displayed to the AI but also to systems the agent is authorised to interact with.

Meta itself acknowledges the significance of the isolation boundary. “Because a Muse agent holds a user’s most sensitive data and can act on their behalf, we treat compromise of that boundary as a first-class security risk,” Meta says on its bug bounty page.

Security researchers have also warned that making the virtualisation boundary part of the production security architecture creates additional risks.

The concerns surrounding Muse come as technology companies increasingly push AI agents beyond conversation and towards autonomous action. The appeal is clear: instead of telling an AI how to complete a task step by step, users can increasingly ask an agent to perform the task for them.

But that convenience also means giving AI systems access to increasingly sensitive parts of people’s digital lives.

The security scare at Meta highlights the problem at the heart of that transition. An AI assistant that can access email, financial information and other personal data must not only understand what a user wants; it must also remain securely contained while carrying out those instructions.

The episode also comes amid growing concern about AI systems escaping their intended environments. AI companies have already faced incidents and warnings involving powerful models breaking containment or being used to launch cyberattacks.

What is Meta Muse?

Meta Muse is an AI-powered personal assistant designed to go beyond answering questions and actually perform tasks for users. The agent can interact with a computer, navigate websites and use applications to carry out actions such as booking flights, shopping online and handling other digital tasks on a user’s behalf.