{"api_version":"1","generated_at":"2026-10-01T04:37:32+00:00","cve":"CVE-2026-92172","urls":{"html":"https://cve.report/CVE-2026-92172","api":"https://cve.report/api/cve/CVE-2026-92172.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-92172","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-92172"},"summary":{"title":"CVE-2026-92172","description":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.","state":"PUBLISHED","assigner":"Meta","published_at":"2026-09-30 21:17:17","updated_at":"2026-10-01 02:17:43"},"problem_types":["Improper Restriction of Communication Channel to Intended Endpoints (CWE-923)"],"metrics":[],"references":[{"url":"https://www.facebook.com/security/advisories/cve-2026-92172","name":"https://www.facebook.com/security/advisories/cve-2026-92172","refsource":"cve-assign@fb.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92172","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92172","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Meta Platforms, Inc","product":"Meta Horizon OS","version":"affected v0.0.0.0.0 v66.0.0.733.524 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Meta Horizon OS","vendor":"Meta Platforms, Inc","versions":[{"lessThan":"v66.0.0.733.524","status":"affected","version":"v0.0.0.0.0","versionType":"semver"}]}],"dateAssigned":"2026-09-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication."}],"problemTypes":[{"descriptions":[{"description":"Improper Restriction of Communication Channel to Intended Endpoints (CWE-923)","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-09-30T20:26:49.629Z","orgId":"4fc57720-52fe-4431-a0fb-3d2c8747b827","shortName":"Meta"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://www.facebook.com/security/advisories/cve-2026-92172"}]}},"cveMetadata":{"assignerOrgId":"4fc57720-52fe-4431-a0fb-3d2c8747b827","assignerShortName":"Meta","cveId":"CVE-2026-92172","datePublished":"2026-09-30T20:26:49.629Z","dateReserved":"2026-09-15T17:32:03.673Z","dateUpdated":"2026-09-30T20:26:49.629Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-30 21:17:17","lastModifiedDate":"2026-10-01 02:17:43","problem_types":["Improper Restriction of Communication Channel to Intended Endpoints (CWE-923)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"92172","Ordinal":"1","Title":"CVE-2026-92172","CVE":"CVE-2026-92172","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"92172","Ordinal":"1","NoteData":"Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication.","Type":"Description","Title":"CVE-2026-92172"}]}}}