Privilege Escalation Vulnerability in Meta Horizon OS
CVE-2026-92173
Currently unrated
What is CVE-2026-92173?
In Meta Horizon OS prior to version 74.0.0.878.1682, a vulnerability exists within the MediaSyncJobReceiver component. This allows an attacker to exploit the system by sending a privileged PendingIntent that includes the CallerIdentity of com.oculus.vrshell to any arbitrary application that listens via the NotificationListenerService. As a result, the compromised application can impersonate the com.oculus.vrshell package and other packages signed with the same key, jeopardizing the security of multiple endpoints within the operating system that utilize CallerIdentity for authentication.
Affected Version(s)
Meta Horizon OS v0.0.0.0.0
