Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-92173

CRITICAL · 9.1 CVSS Gepubliceerd: CWE-923

Beschrijving NL

Voorafgaand aan v74.0.0.878.1682 van Meta Horizon OS, kon MediaSyncJobReceiver ertoe worden gebracht om een geprivilegieerde PendingIntent te verzenden, inclusief een com.oculus.vrshell CallerIdentity naar een willekeurige toepassing die luistert via NotificationListenerService. Dat zou de applicatie in staat stellen om zich voor te doen als het com.oculus.vrshell-pakket, evenals pakketten die met dezelfde sleutel zijn ondertekend, naar elk eindpunt binnen het besturingssysteem dat CallerIdentity-authenticatie gebruikt.

Origineel (Engels) tonen

Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.

References