CVE-2026-92173
published 2026-09-30CVE-2026-92173: Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell…
PriorityP260critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.29%
19.5th percentile
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| meta_platforms_inc | meta_horizon_os | >= v0.0.0.0.0 < v74.0.0.878.1682 | v74.0.0.878.1682 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listeni
ghsa_unreviewed·2026-09-30
CVE-2026-92173 Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listeni
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
VulDB
Meta Platforms Meta Horizon OS 66.0.0.733.524 MediaSyncJobReceiver communication channel to intended endpoints
vuldb·2026-09-30
CVE-2026-92173 [CRITICAL] Meta Platforms Meta Horizon OS 66.0.0.733.524 MediaSyncJobReceiver communication channel to intended endpoints
A vulnerability was found in Meta Platforms Meta Horizon OS 66.0.0.733.524. It has been classified as critical. This affects an unknown part of the component MediaSyncJobReceiver. The manipulation leads to improper restriction of communication channel to intended endpoints.
This vulnerability is listed as CVE-2026-92173. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-30
Published