Meta Fixed a Muse VM Escape Flaw Just 11 Days Before Launch
Meta identified multiple vulnerabilities in Muse's virtualization boundary 11 days before its September 8 launch, including a KVM escape serious enough to reach Mark Zuckerberg. Meta's bug bounty pays up to $300,000 for breaching the Muse-to-production boundary. After launch, researcher Patrick Wardle disclosed a macOS zero-day in the app.
- Flaws found 11 days before Muse's September 8 launch
- Meta's bug bounty pays up to $300,000 for production boundary breaches
- A macOS zero-day in Muse was disclosed after launch
- Meta shipped a hotfix, calling it a local privilege-escalation issue
Read next
AI