CyberRota Analysis
AI-GeneratedMeta Horizon OS versions prior to v74.0.0.878.1682 contain a vulnerability in MediaSyncJobReceiver that allows an arbitrary application to receive a privileged PendingIntent, enabling it to impersonate the com.oculus.vrshell package and any other packages signed with the same key. This could lead to unauthorized access and manipulation of sensitive operations within the OS that rely on CallerIdentity authentication. Developers and security teams managing applications that interact with Meta Horizon OS should prioritize addressing this vulnerability to mitigate potential exploitation risks.
Original NVD Description
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.