Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-92172

HIGH · 8.8 CVSS Gepubliceerd: CWE-923

Beschrijving NL

Voorafgaand aan v66.0.0.733.524 van Meta Horizon OS, zou OVRMediaService ertoe kunnen worden gebracht om een geprivilegieerde PendingIntent inclusief een com.oculus.horizon CallerIdentity naar een willekeurige applicatie te sturen die zich registreert voor com.oculus.systemactivities.SCREENSHOT via een uitzendontvanger. Dat zou de applicatie in staat stellen om zich voor te doen als het com.oculus.horizon-pakket naar elk eindpunt binnen het besturingssysteem dat CallerIdentity-authenticatie gebruikt.

Origineel (Engels) tonen

Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.

References