OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92172

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The OVRMediaService in Meta Horizon OS versions prior to 66.0.0.733.524 is vulnerable to a privilege escalation attack, allowing arbitrary applications to receive a privileged PendingIntent that can impersonate the com.oculus.horizon package. This could enable unauthorized access to sensitive operations within the OS that rely on CallerIdentity authentication. Developers and security teams managing applications that interact with Meta Horizon OS should prioritize addressing this vulnerability to mitigate potential exploitation risks.

CVE
CVE-2026-92172
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.