Zuckerberg pushed Muse’s release despite safety delays, Futurism reports
The new account adds scrutiny to a prelaunch security scramble: 404 Media found that one flaw could have exposed sensitive Meta databases.
Loading page…
The new account adds scrutiny to a prelaunch security scramble: 404 Media found that one flaw could have exposed sensitive Meta databases.
Listen to this story
Futurism reported, citing The New York Times, that Mark Zuckerberg pressed ahead with Meta’s Muse agent after rival Instinct launched, despite safety delays. Separate reporting by 404 Media describes a prelaunch effort, begun August 27 ahead of Muse’s September 8 release, to address virtual-machine escape risks that could have exposed internal systems; it found a potential attack path, not a confirmed breach. The episode highlights the operational stakes of hosting user agents inside production infrastructure, even with layered controls.
Meta’s design gives each user a dedicated Linux cloud computer, with agent containers separated from sensitive services and limited in filesystem, operating-system, and kernel access.
A separate service called Sentinel can allow, deny, or request user approval for connected-service actions and outgoing network requests.
Meta said employee use, adversarial testing, and bug-bounty work strengthened Muse’s safeguards; its bounty terms offer $300,000 for a virtual-machine escape.
Mark Zuckerberg pushed Meta’s Muse AI agent toward release after safety problems delayed development for months, Futurism reported on October 10, citing the New York Times. The account adds scrutiny to a prelaunch security scramble documented by 404 Media, including a flaw that could have let a Muse user reach sensitive internal Meta databases.
Futurism’s account says Zuckerberg decided to release Muse after rival agent Instinct launched. The more detailed account of the database risk comes from 404 Media’s October 5 investigation. Reporter Jason Koebler cited an anonymous Meta source, internal security documents and executive posts.
A virtual-machine escape lets software break out of its assigned computer environment and interact with the system hosting it or other users’ environments. Several reported Muse flaws lay in the underlying Linux virtualization software. The database exposure was a potential attack path, not a confirmed malicious breach.
A September 18 internal executive post described a spike in reported escapes from kernel-based virtual machines, or KVMs. It said the security effort began August 27 and lasted several weeks and weekends. Meta’s own launch post dates Muse’s release to September 8.
Teams reduced what agents could access and restricted reachable network addresses and ports. Multiple security teams worked nights and weekends, and the issues reached Zuckerberg. An anonymous employee told 404 Media that teams were pressured to fix bugs without delaying launch, calling the protections rushed and “half-baked.”
With Muse, we are directly hosting and running agents on behalf of end users, a fundamentally different paradigm
Meta infrastructure executives, in a September 18 internal post reviewed by 404 Media
Meta’s September 8 technical explanation, How We Built Safety Into Muse, describes a dedicated Linux cloud computer for each user. Within it, the agent’s container—a restricted working environment—is separated from sensitive services. Administrative privileges inside that container do not grant administrative control of the host.
Security researcher Patrick Wardle told 404 Media that the deeper concern is placing user-controlled virtual machines within Meta’s live production environment. In his assessment, a KVM failure or flaw in an accessible internal service could turn user code into access to company systems.
Meta told 404 Media it strengthened Muse through employee use, adversarial testing and its bug bounty program, with work continuing. Its bounty terms list $300,000 for a virtual-machine escape; reaching production services or internal networks falls in the highest-risk category.
Loading discussion...
Join the conversation
Explain whether that history would change your trust in an assistant.
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.