{"id":"CVE-2026-92172","title":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREEN…","summary":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREEN…","severity":"none","cwe":["CWE-923"],"vendor":"Meta Platforms, Inc","product":"Meta Horizon OS","affected":["meta_horizon_os >= v0.0.0.0.0 < v66.0.0.733.524"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T21:17:17.100","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92172","references":[{"url":"https://www.facebook.com/security/advisories/cve-2026-92172","label":"cve-assign@fb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T21:25:07.846Z","slug":"CVE-2026-92172","body":"## Overview\n\nPrior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}