Meta discovered serious security flaws in its Muse AI agent before the product launched. Reports showed that one vulnerability could have let users access sensitive data. Meta started fixing these issues on August 27. Teams worked nights and weekends to secure the system before the AI agent finally got released.

Meta reportedly discovered several serious security vulnerabilities in Muse, its personal AI agent, in the weeks before the product launched. If left unchecked, one of the flaws could have allowed Muse users to break into Meta’s systems and access sensitive data, according to 404 Media. The issues were reportedly so serious that Meta staff raised it with CEO Mark Zuckerberg, and teams worked nights and weekends to fix them.

Muse is an AI agent that can work on a user’s behalf, including accessing services such as email, calendars, messaging and other accounts. To keep it separate from Meta’s main systems, Muse runs inside its own virtual machine. Think of this as a separate, protected space where Muse can work without directly accessing Meta’s wider systems. The idea is that even if something goes wrong inside Muse, it should stay within that space.

But this is where the security problem came in. According to the report, one of the vulnerabilities was linked to an exploit found in Linux’s virtual machine code in July. If exploited, it could have allowed a Muse user to break out of the protected environment and access the larger system running it.

According to the report, which cited a Meta source and internal security documents, at least one of these flaws could have allowed a normal Muse user to access sensitive data inside Meta’s systems. Meta reportedly started seeing more reports of these security problems and brought together several teams to fix them.

The security work was also mentioned in an internal post by Meta executives on September 18. The post said the company started working on the issue on August 27, with teams working for several weeks, including weekends. Engineers also tried to limit what Muse could access and which parts of the internet and Meta’s systems it could connect to.

The concern was bigger because Muse is not just a chatbot. It can access a user’s accounts and carry out tasks for them. So, if someone found a way to break through its security, they could potentially gain access to much more than a normal chatbot conversation.

Meta says it has strengthened Muse’s security through extensive testing, internal security checks and its bug bounty programme.

Nevertheless, this is not the first security incident involving Muse. The AI agent has faced more scrutiny since its launch. Security researcher Patrick Wardle recently found another vulnerability that could allow apps and terminal commands to control a user’s Muse. Another user also reportedly managed to make Muse export Instagram followers, something that should not have been possible.

- Ends