2 hrs ago
Meta Rushed to Address Muse AI Security Flaws Before Launch
Muse is an AI agent made by Meta that can do tasks using connected accounts.
Because it can reach email, calendars and other services, it runs inside a protected computer environment.
A report said Meta found serious security problems in Muse before launch.
One problem might have let a user break out of that protected environment and reach sensitive Meta systems.
Meta reportedly brought teams together to fix the problems, and engineers worked weekends.
They also limited which services and systems Muse could reach.
Meta said it used testing, security reviews and its bug bounty programme to improve safety.
Other reported Muse issues have also drawn attention to the risks of AI agents.
A report said Meta found serious security vulnerabilities in its Muse AI agent weeks before launch.
One reported flaw could potentially have let a regular Muse user escape its virtual machine and access sensitive Meta systems.
Meta reportedly began addressing the issues on August 27, with work continuing through weekends.
Engineers restricted Muse’s access to services, the internet and Meta’s internal infrastructure.
Meta said it strengthened Muse’s security through testing, internal reviews and its bug bounty programme.
- Who
- Meta and its engineering and security teams; the report also mentions CEO Mark Zuckerberg and security researcher Patrick Wardle.
- What
- Meta reportedly addressed serious security vulnerabilities in its Muse AI agent before launch.
- Where
- Within Muse’s virtual-machine environment and Meta’s systems; no specific physical location is stated.
- When
- Work reportedly began August 27 and continued for several weeks; an internal executive post was dated September 18.
- Why
- The vulnerabilities could potentially let a Muse user escape its protected environment and access sensitive Meta data.
Key facts
- Product
- Muse, Meta’s personal AI agent
- Reported work start
- August 27
- Internal post date
- September 18
- Reported vulnerability
- A flaw could potentially allow escape from Muse’s virtual machine and access to sensitive Meta systems.
- Mitigations described
- Meta reportedly limited Muse’s access to services, the internet and internal infrastructure.
- Meta’s stated security measures
- Extensive testing, internal security reviews and a bug bounty programme
- Other reported concerns
- Patrick Wardle identified a vulnerability involving applications and terminal commands; a user reportedly got Muse to export Instagram followers.










