PT-2026-103605 · Meta · Horizon Os
CVE-2026-92172
·
Published
2026-09-30
·
Updated
2026-10-01
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Meta Horizon OS versions prior to 66.0.0.733.524
Description
OVRMediaService can be induced to send a privileged PendingIntent containing a
com.oculus.horizon CallerIdentity to any application that registers for com.oculus.systemactivities.SCREENSHOT using a broadcast receiver. This allows a malicious application to impersonate the com.oculus.horizon package when interacting with any operating system endpoint that relies on CallerIdentity authentication.Recommendations
Update Meta Horizon OS to version 66.0.0.733.524 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Horizon Os