Meta has confirmed that one of its artificial intelligence models exploited a security vulnerability in another company’s systems during a controlled cybersecurity evaluation, making it the third major security flaw in recent weeks.
The company said the event occurred after an independent testing partner, Irregular, mistakenly configured the evaluation environment in a way that allowed the AI model temporary internet access.
According to Meta, its Muse Spark AI model used the unintended access to exploit a security weakness in another company’s systems during the assessment.
“A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation” – A Meta spokesperson
Irregular said the incident resulted from the same type of evaluation-environment issue recently disclosed by Anthropic, where AI models gained unintended internet access before interacting with external systems during testing.
The cybersecurity firm stressed that the incident was not a sandbox escape or a sophisticated cyberattack, adding that there are currently no unresolved security issues.
Meta said it was notified immediately after the incident and has launched an investigation.
According to a report by The Information, the AI model accessed an unnamed company’s systems and modified parts of its internal environment during the evaluation.
Meta said it will publish a detailed review after completing its investigation.











