PT-2026-103605 · Meta · Horizon Os

CVE-2026-92172

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Meta Horizon OS versions prior to 66.0.0.733.524
Description OVRMediaService can be induced to send a privileged PendingIntent containing a com.oculus.horizon CallerIdentity to any application that registers for com.oculus.systemactivities.SCREENSHOT using a broadcast receiver. This allows a malicious application to impersonate the com.oculus.horizon package when interacting with any operating system endpoint that relies on CallerIdentity authentication.
Recommendations Update Meta Horizon OS to version 66.0.0.733.524 or later.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92172

Affected Products

Horizon Os