Privilege Escalation Vulnerability in Meta Horizon OS
CVE-2026-92173

Currently unrated

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-92173?

In Meta Horizon OS prior to version 74.0.0.878.1682, a vulnerability exists within the MediaSyncJobReceiver component. This allows an attacker to exploit the system by sending a privileged PendingIntent that includes the CallerIdentity of com.oculus.vrshell to any arbitrary application that listens via the NotificationListenerService. As a result, the compromised application can impersonate the com.oculus.vrshell package and other packages signed with the same key, jeopardizing the security of multiple endpoints within the operating system that utilize CallerIdentity for authentication.

Affected Version(s)

Meta Horizon OS v0.0.0.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.