AI News Feed
Market watch
Cybersecurity

Meta Rushed to Fix Muse 'VM Escape' Bugs Before Launch

Meta engineers found several security flaws in its Muse AI agent before launch, including at least one that could let a normal user reach sensitive internal databases, according to 404 Media.

404 Media cited an internal post from Meta executives to the company's core infrastructure team that described a multi-team 'mad dash' to fix 'a sudden spike in reported KVM escapes.' Muse runs each instance on a kernel-based virtual machine, which connects to but is meant to be isolated from Meta's critical infrastructure. A KVM escape occurs when a vulnerability allows a Muse instance to leave that virtual machine and interact with the system that runs it or with other users' virtual machines.

For Muse to work, a user gives the AI agent access to important services and accounts they own. According to a Meta source and internal security documentation and posts reviewed by 404 Media, at least one of the vulnerabilities could have allowed an outside attacker -- a normal Muse user -- to access data in sensitive internal Meta databases. At least one vulnerability was related to an exploit found in Linux kernel-based virtual machine code in July. Several of the flaws were in the underlying Linux virtualization software Meta uses for Muse.

The security issue was considered serious enough to be raised to Zuckerberg. Several different security teams worked nights and weekends in the leadup to launch to fix the issues, according to the report. The Meta source said they felt security teams were asked to push hot fixes to these bugs as quickly as possible and in a way that would not delay Muse's launch. The source described 'half-baked protections being rushed out to enable the launch' and said many senior engineers believe a massive data breach is inevitable as a result of Hatch. Muse is called 'Hatch' internally and in Meta's codebase.

Editor's Summary

Meta found several security vulnerabilities in Muse before launch, including at least one KVM escape that could have exposed sensitive internal data to a normal user, according to 404 Media. The issues reached Mark Zuckerberg and prompted security teams to work overtime on fixes while avoiding launch delays. Meta internally calls the product Hatch.