CVE-2026-92172

Summary

Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.

Affected Software

VendorProductVersion RangeStatus
Meta Platforms, IncMeta Horizon OSv0.0.0.0.0 < v66.0.0.733.524affected

Weaknesses

  • Improper Restriction of Communication Channel to Intended Endpoints (CWE-923)

References