External risk intelligence

Meta Horizon OS MediaSyncJobReceiver CallerIdentity Spoofing Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-92173

This vulnerability exists within the internal IPC (Inter-Process Communication) mechanisms of the Meta Horizon OS. It involves a local receiver and internal OS-level identity handling between local packages. It does not involve public-facing network services, external APIs, or internet-accessible interfaces.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in Meta Horizon OS, impacting how certain internal communications are handled. This issue could potentially allow unauthorized applications to impersonate legitimate system components, which warrants investigation into its relevance and exposure within our environment.

  • A flaw allows apps to mimic system functions.
  • Internal OS communication is the concern.
  • Confirm if this affects our Meta Horizon OS use.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a malicious application to impersonate a core system component, like the `com.oculus.vrshell` package, by exploiting a vulnerability in how the Meta Horizon OS handles privileged intents. This allows the attacker's application to gain the same identity and permissions as the system component, potentially leading to unauthorized access or actions within the operating system when interacting with services that rely on identity-based authentication.

  • No authentication needed.
  • Triggered by a listening app.
  • Risk of impersonation and privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a malicious application to impersonate the `com.oculus.vrshell` package or other applications signed with the same key. This impersonation could occur when the `MediaSyncJobReceiver` sends a privileged `PendingIntent` to a listening `NotificationListenerService`, provided the conditions for such an interaction are met within the operating system.

  • System package identity at risk.
  • Malicious app spoofs legitimate package.
  • Unauthorized actions within the OS.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Meta Horizon OS's MediaSyncJobReceiver could allow an arbitrary application to impersonate the `com.oculus.vrshell` package and access privileged information. The first practical step is to identify all deployed Meta Horizon OS instances, determine their reachability and business criticality, and locate the accountable system owner. Subsequently, a risk-based remediation plan should be developed, coordinating with relevant platform or application teams.

  • Platform and application owners should address this.
  • Verify Meta Horizon OS instance presence and reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Meta Horizon OS?

Meta Horizon OS is the underlying software platform that powers Meta’s virtual and mixed reality headsets. It manages core hardware resources, system-level services, and the interactions between installed applications, providing the framework for the device's immersive environments and user interface.

How does CVE-2026-92173 work?

This vulnerability involves a weakness class known as Improper Restriction of Communication Channel to Intended Endpoints (CWE-923). Essentially, a system component mistakenly shares privileged identity information with an untrusted app, allowing that app to masquerade as a legitimate, trusted system service.

Do I need to worry about network attacks for this bug?

No. The issue is triggered by specific internal interactions between applications already present on the device. It cannot be triggered by remote network requests or external web traffic, as it relies on local Inter-Process Communication mechanisms within the operating system.

Why is this vulnerability relevant to my environment?

According to Halo Surface Signal, this risk is very unlikely to be remotely reachable. Because the vulnerability is confined to internal OS-level identity handling and local packages, it does not involve public-facing interfaces or services accessible from the internet.

When should I update my Meta Horizon OS devices?

You should prioritize identifying all Meta Horizon OS devices in your organization and confirming which versions they are running. The primary step is to coordinate with the relevant platform owners to plan for updates to version 74.0.0.878.1682 or later, which contains the fix for this issue.

References