HomeSecurityIs Meta's VR headset vulnerable to ransomware attacks? - Research

Is Meta's VR headset vulnerable to ransomware attacks? - Research

Hacking attacks on VR headsets are rare. However, the first ransomware attack against the Apple Vision Pro was reported only in the second week of June 2024.

VR headset ransomware

A researcher has presented a method for installing malware on Meta's Quest 3 headset.

Read also: Meta's Horizon Worlds: Released wherever the Quest Headset is sold

Researcher Harish Santhanalakshmi Ganesan reported on Reddit that installing malware on the Quest 3 VR is nearly impossible. As a personal challenge to explore new threats, he decided to do it without enabling developer mode.

A simple Google revealed that Meta uses a customized version of the Android Open Source Project (AOSP). “This means I can install any APK just like I would on an Android phone,” he said.

Further research on YouTube led him to a methodology that uses an app from Meta's App Lab, giving access to Android's native file manager. "I used this method to install the ransomware on my headset," he explained.

See also: Meta: Stops training AI with user data

CovidLock is a ransomware targeting Android devices, disguised as a COVID-19 tracking app. It uses permission abuse to gain additional privileges. If successful, it locks users out of the device and displays a ransom note.

However, the malware the researcher installed doesn't matter – the process he discovered could deliver any malware through social engineering.

“This research is not about a vulnerability in Meta Quest 3, but an attack surface that allows malware to be installed without enabling developer options,” he told SecurityWeek. While he hasn’t released the technical details of the method, he believes it wouldn’t be difficult for malicious users to replicate the process.

Read also: Logitech Introduces MX Ink for Meta Quest 2 and 3

He doesn't expect Meta to actively react to his research, as it doesn't technically involve a vulnerability, but rather focuses on social engineering.

“This means that any hacker could use social engineering to trick a user into installing a malicious app on the Quest and making it a device administrator without enabling developer mode,” he told SecurityWeek. “Hypothetically, hackers could create ransomware and spread it via a YouTube video about installing third-party software without a computer, thereby spreading the (malicious) APK.”

VR headset ransomware

Since there is no technical vulnerability, no patch is expected. The researcher published his paper to warn VR users to beware of social engineering. The main advice is the same as that given to all smartphone users: Avoid sideloading.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See more: VR game “Demeo” now available for Apple Vision Pro

Source: securityweek

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS