---
title: "Meta Fixes Muse VM Vulnerability Rated SEV-2 · AgentDots"
description: "Meta has patched a SEV-2 Muse flaw, found through its bug bounty programme, which put at risk the Muse Secure VM holding a user's emails and files."
url: https://agentdots.org/news/meta-fixes-muse-vm-bug/
lang: en
---

Safety

# Meta fixes a Muse flaw that could have opened users' virtual machines

Reported through Meta's bug bounty programme, the bug put at risk the cloud machine where Muse keeps copies of a user's emails and files.

September 25, 2026

Meta has fixed a security vulnerability in Muse that might have allowed an attacker to get inside the virtual machine assigned to an individual user, Reuters reported in a story carried by ETCISO on 25 September. The flaw was found by a researcher and reported through Meta's bug bounty programme. Meta classed it as SEV-2, the second-highest rating on its severity scale.

The stakes are set by how Muse is built. Every account is given a Muse Secure VM, a cloud machine that runs the agent and keeps copies of whatever emails and files the user connects. A way into that machine would therefore be a way into much of the user's digital life, or at least the parts they had linked to the agent.

Meta also used the fix as an occasion to make the Muse app's safety warnings clearer. The report did not say whether the flaw had been exploited. The disclosure came in a difficult month for the agent, which had already lost access to Amazon's store and, three days later, was reported to have shared a user's home address.

What it means for you

Update the Muse app and pay attention to its warnings. Connect an account only when a task you are running actually needs it, because each one adds to what a single flaw could reveal.

**Sources**

- [Reuters via ETCISO](https://ciso.economictimes.indiatimes.com/news/vulnerabilities-exploits/meta-bolsters-muse-safety-warning-after-security-vulnerability-found/134530548)

## About

- [Muse](https://agentdots.org/agents/muse/)

## Incidents

- [Flaw opened a possible route into Muse machines](https://agentdots.org/incidents/muse-vm-vulnerability/)

## More news

September 29, 2026
[OpenAI unveils Dots, persistent agents that carry on once you log off](https://agentdots.org/news/openai-launches-dots/)

September 29, 2026
[GPT-6.1 Sol halves cached input, cutting the cost of long agent tasks](https://agentdots.org/news/gpt-6-1-sol-price/)

September 29, 2026
[ChatGPT Pro adds a $500 tier as the $200 plan loses allowance](https://agentdots.org/news/chatgpt-pro-500/)

September 29, 2026
[Australia receives an OpenAI apology over an agent's Medicare portal breach](https://agentdots.org/news/openai-apologises-to-australia/)

September 28, 2026
[OpenAI shelves GPT-6.1 Astra a day before DevDay](https://agentdots.org/news/openai-shelves-astra/)

September 28, 2026
[Muse told a Marketplace buyer where its owner lived, reviewer says](https://agentdots.org/news/muse-gave-out-address/)
