← Registry

CPATH-2026-0011 · SMART GLASSES AR

SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence PERCEPTION_TO_ACTION perception · Evidence EV:1 (inferred) · Liveness PATCH_AVAILABLE
CPATH IDCPATH-2026-0011
CVE(s)CVE-2024-21625
Device / classSideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625) (SMART GLASSES AR)
VendorMeta
Dominant consequencePERCEPTION_TO_ACTION (perception)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline
v3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · GitHub Advisory via NVD / NVD
Baseline relationship▼ Paths higher
Consequence dimension(s)#1 #2 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

perception

PERCEPTION_TO_ACTION

CRITICAL
Reachability RE:4
Complexity EC:3
Consequence PERCEPTION_TO_ACTION
Scale SR:4 / SX:3
Verdict CRITICAL
Reachability 4
Complexity 3
Exposure 3
Physical / safety 2
Data / perception 4
Authority 3
Chainability 4
Reuse scale 4
Execution scale 3
Recovery 2
Evidence EV:1 · inferred
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:4/SR:4/SX:3/OR:2/EV:1/LS:PATCH_AVAILABLE

authority

ACCOUNT_AUTHORITY

CRITICAL
Reachability RE:4
Complexity EC:4
Consequence ACCOUNT_AUTHORITY
Scale SR:4 / SX:3
Verdict CRITICAL
Reachability 4
Complexity 4
Exposure 4
Physical / safety 2
Data / perception 3
Authority 2
Chainability 4
Reuse scale 4
Execution scale 3
Recovery 2
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Assessment

CFSE Consequence Paths assesses SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625) at CRITICAL — the worst of 2 risk paths (perception, authority). The dominant consequence is manipulated perception that drives action.

Vulnerability

SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625). Reported attack vector: NETWORK (one-click, requires user interaction).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:3/EX:3/PH:2/DP:4/AT:3/CH:4/SR:4/SX:3/OR:2/EV:1/LS:PATCH_AVAILABLE

Exposure EX=3 (execution complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=CRITICAL → base CRITICAL → assessed CRITICAL.

Same internet-reachable one-click entry (RE:4). Post-RCE pivot uses SideQuest’s brokered ADB to push arbitrary APKs to the connected headset - standard researcher workflow once code-exec is held, with the extra step requiring a connected device (EC:3). Installing attacker code on the headset is service/command-level authority over the device’s installed software (AT:3). A malicious sideloaded VR app can read headset sensor/camera/spatial/account state and manipulate the immersive display, i.e. control the user’s perceived AR reality (DP:4, perception_feeds_action:true). No direct dangerous actuator or therapy; harm is disorientation/manipulated immersive environment rather than credible injury (PH:2). Web->desktop->device->perception boundary chain and reusable cross-domain bridge (CH:4, boundary_crossing:true). Single mass-distributable payload pushing the same APK = reuse across many setups (SR:4), gated by per-victim connected-headset click (SX:3). Recovered by app patch plus removing the pushed app, no signing-root rotation (OR:2). Headset-pivot step is modelled/inferred from the brokering capability rather than reproduced in the report (EV:1).

ACCOUNT_AUTHORITYCRITICAL

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:4/EX:4/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:2/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=CRITICAL → base CRITICAL → assessed CRITICAL.

Internet-reachable malicious sidequest:// link (RE:4); single crafted link, one click, commodity Electron deep-link abuse (EC:4). Yields arbitrary code execution at the PC user’s privilege inside the SideQuest process - bounded user-level host/account authority, not root-of-trust or admin (AT:2). Arbitrary code can read PC user data and SideQuest-stored credentials/tokens (DP:3). Crosses web->desktop-app boundary and is a reusable bridge to ADB/headset control, so high chainability and boundary crossing (CH:4). One payload mass-distributable via phishing/forum posts to VR communities = deployment-wide reuse of a single artifact (SR:4), but still requires victim click with SideQuest running so not zero-touch fleet remote (SX:3). Patchable by app update, no fleet/key rotation (OR:2). Report-backed CVE (EV:2).

Published baseline

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0011 (“SideQuest deep-link one-click RCE on Oculus Quest sideloading platform (CVE-2024-21625)”), paths.cfse.ai/CPATH-2026-0011 (published 2026-06-03).