Tidavo
Tuesday 6 October 2026

Flaws in Meta Assistant Software Let Users Break Into Company Core Systems

Engineers hurried across late nights to plug system holes before releasing their new personal digital helper.

6 Oct 2026

Meta put its new artificial intelligence assistant into the hands of the public shortly after finding severe digital weaknesses inside the software.

The product is known publicly as Muse and internally by the code name Hatch. It manages personal tasks like scheduling trips, booking dining tables, and dropping paid subscriptions.

People connect their own outside accounts, including personal calendars and electronic mail, directly to the assistant so it can act in their place.

To protect private data, the system places each separate user assistant into its own digital holding pen, known as a virtual machine. This software barrier is supposed to keep the assistant walled off from Meta's main network.

Just weeks ahead of public distribution, engineers detected flaws that could allow an ordinary customer to climb outside that partition. Breaking out would give someone access to the underlying computer systems and Meta's sensitive company databases.

Meta considers such a breakout to be its highest tier of danger. The firm promises to hand over three hundred thousand dollars to any independent researcher who uncovers a flaw letting someone escape the digital sandbox.

The danger was brought to Mark Zuckerberg's desk as staff faced a sudden climb in reported partition breaches. Several company teams worked through weekends and late hours to patch the holes.

Part of the danger stemmed from underlying Linux operating code that had an exploit identified in July.

An internal message sent ten days after launch confirmed that a hardening project started on August twenty-seventh. Company executives Surupa Biswas, Francois Richard, and Josh Barry told infrastructure staff that the rush lasted a few weeks and weekends.

Those teams worked to shrink the areas the assistant could reach and blocked off specific network ports and addresses from the host computers.

An internal employee stated that the scramble produced hasty fixes aimed at keeping the launch date intact. That source warned that experienced engineers fear a massive company data loss will eventually happen.

Independent specialists have noted other security gaps since the software went live. Researcher Patrick Wardle found an unknown flaw that let computer terminal commands take over a person's assistant.

Another customer managed to make the tool scrape and list his Instagram followers and their followers, prompting a review by internal security investigators.

Meta defended its safety measures, stating that it trained staff to test the tool, ran attack simulations, and continues to monitor weaknesses through its reward initiative.

404 Media , 404 Media