CPATH-2026-0011 · Smart glasses / AR

SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsPerception-to-action + Account authority

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Perception · Co-dominant path

Perception-to-action

A malicious SideQuest deep link can place attacker code in the headset workflow, enabling software that changes the virtual environment the wearer trusts.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    The deep link can be delivered through attacker-controlled web content to a user who has SideQuest installed.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Web to desktop to device to perception boundary chain and reusable cross-domain bridge (true).

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    A malicious SideQuest deep link can place attacker code in the headset workflow, enabling software that changes the virtual environment the wearer trusts.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception-to-action

    A malicious SideQuest deep link can place attacker code in the headset workflow, enabling software that changes the virtual environment the wearer trusts.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Recovered by app patch plus removing the pushed app, no signing-root rotation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The deep link can be delivered through attacker-controlled web content to a user who has SideQuest installed.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Post-remote code execution pivot uses SideQuest's brokered ADB to push arbitrary APKs to the connected headset - standard researcher workflow once code-exec is held, with the extra step requiring a connected device.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Changing the immersive environment can disorient the wearer, but the record does not establish a credible injury.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

A malicious SideQuest deep link can place attacker code in the headset workflow, enabling software that changes the virtual environment the wearer trusts.

Model inference
AuthorityAT 3
Administrative or command authority

Installed headset software can control the rendered experience and device services without reaching the firmware or signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Web to desktop to device to perception boundary chain and reusable cross-domain bridge (true).

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Single mass-distributable payload pushing the same APK is reuse across many setups, gated by per-victim connected-headset click.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

The same malicious deep link can be distributed broadly, but every target must open it while a headset is connected to the affected SideQuest session.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Recovered by app patch plus removing the pushed app, no signing-root rotation.

Operational assumption
Confidence and status
Evidence strengthEV 1
Analyst inference

The SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625) consequence rests on limited public evidence and remains explicitly provisional.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. A malicious SideQuest deep link can place attacker code in the headset workflow, enabling software that changes the virtual environment the wearer trusts.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:4/SR:4/SX:3/OR:2/EV:1/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Account authority

Code execution inherits the logged-in PC user’s privileges inside SideQuest, giving bounded host authority rather than administrator, root, or signing authority.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    Internet-reachable malicious SideQuest deep link link.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The deep link crosses from web content into the desktop application and can bridge through ADB to headset software.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Bounded function authority

    Code execution inherits the logged-in PC user’s privileges inside SideQuest, giving bounded host authority rather than administrator, root, or signing authority.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    Code execution inherits the logged-in PC user’s privileges inside SideQuest, giving bounded host authority rather than administrator, root, or signing authority.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Updating SideQuest removes the vulnerable handler; no fleet-wide key rotation or device reprovisioning is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Internet-reachable malicious SideQuest deep link link.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Single crafted link, one click, commodity Electron deep-link abuse.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Arbitrary software installed on an immersive headset can alter the wearer's rendered environment and create serious disorientation risk; this record does not claim an observed injury.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Code running as the PC user can read that user’s files and SideQuest credentials or tokens.

Model inference
AuthorityAT 2
Bounded function authority

Code execution inherits the logged-in PC user’s privileges inside SideQuest, giving bounded host authority rather than administrator, root, or signing authority.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The deep link crosses from web content into the desktop application and can bridge through ADB to headset software.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same deep-link payload can be distributed through posts or messages to many SideQuest users, but every compromise still depends on a target opening it.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

One deep-link payload can be reused across many SideQuest users, while each target still has to open it with a connected headset.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Updating SideQuest removes the vulnerable handler; no fleet-wide key rotation or device reprovisioning is required.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. code execution inherits the logged-in PC user’s privileges inside SideQuest, giving bounded host authority rather than administrator, root, or signing authority.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the perception transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 8.8 HIGHGitHub Advisory via NVD / NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625) at CRITICAL — the worst of 2 risk paths (perception, authority). The dominant consequence is manipulated perception that drives action.

Vulnerability

SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625). Reported attack vector: NETWORK (one-click, requires user interaction).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:4/SR:4/SX:3/OR:2/EV:1/LS:PATCH_AVAILABLE

Exposure EX=3 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=CRITICAL → base CRITICAL → assessed CRITICAL.

Same internet-reachable one-click entry (RE:4). Post-RCE pivot uses SideQuest’s brokered ADB to push arbitrary APKs to the connected headset - standard researcher workflow once code-exec is held, with the extra step requiring a connected device (EC:3). Installing attacker code on the headset is service/command-level authority over the device’s installed software (AT:3). A malicious sideloaded VR app can read headset sensor/camera/spatial/account state and manipulate the immersive display, i.e. control the user’s perceived AR reality (DP:4, perception_feeds_action:true). No direct dangerous actuator or therapy; harm is disorientation/manipulated immersive environment rather than credible injury (PH:2). Web->desktop->device->perception boundary chain and reusable cross-domain bridge (CH:4, boundary_crossing:true). Single mass-distributable payload pushing the same APK = reuse across many setups (SR:4), gated by per-victim connected-headset click (SX:3). Recovered by app patch plus removing the pushed app, no signing-root rotation (OR:2). Headset-pivot step is modelled/inferred from the brokering capability rather than reproduced in the report (EV:1).

ACCOUNT_AUTHORITYCRITICAL

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL → assessed CRITICAL.

Internet-reachable malicious sidequest:// link (RE:4); single crafted link, one click, commodity Electron deep-link abuse (EC:4). Yields arbitrary code execution at the PC user’s privilege inside the SideQuest process - bounded user-level host/account authority, not root-of-trust or admin (AT:2). Arbitrary code can read PC user data and SideQuest-stored credentials/tokens (DP:3). Crosses web->desktop-app boundary and is a reusable bridge to ADB/headset control, so high chainability and boundary crossing (CH:4). One payload mass-distributable via phishing/forum posts to VR communities = deployment-wide reuse of a single artifact (SR:4), but still requires victim click with SideQuest running so not zero-touch fleet remote (SX:3). Patchable by app update, no fleet/key rotation (OR:2). Report-backed CVE (EV:2).

Published baseline

  • v3.1 8.8 HIGH — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — GitHub Advisory via NVD / NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0011 (“SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)”), paths.cfse.ai/CPATH-2026-0011 (published 2026-06-03).