Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Perception · Co-dominant path
Perception-to-action
A malicious VR app can replace the rendered environment and interaction state that the wearer trusts, allowing manipulated perception to steer safety-relevant actions.
Proximity or local access
The attacker must share the victim's Wi-Fi network, and the headset must have developer mode enabled; the path is not exposed to the open internet by default.
EvidenceNo direct citation — inspect the declared inference or assumption.
Cross-domain authority chain
Bridges network to app overlay to device perception to user physical and decision domain.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
A malicious VR app can replace the rendered environment and interaction state that the wearer trusts, allowing manipulated perception to steer safety-relevant actions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception-to-action
A malicious VR app can replace the rendered environment and interaction state that the wearer trusts, allowing manipulated perception to steer safety-relevant actions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
High stealth, hard to observe once established, recoverable by configuration (disable dev mode and untrusted networks) without fleet reprovision.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must share the victim's Wi-Fi network, and the headset must have developer mode enabled; the path is not exposed to the open internet by default.
- Execution complexity
EC 2 - Specialist multi-step technique
The demonstrated setup combines local-network access, application sideloading, and a convincing full-screen overlay in a specialist but repeatable workflow.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Control of the rendered visual field can disorient the wearer and provoke unsafe movement, although the study did not demonstrate a severe injury.
- Data / perception
DP 4 - Safety-driving perception or intimate data
A malicious VR app can replace the rendered environment and interaction state that the wearer trusts, allowing manipulated perception to steer safety-relevant actions.
- Authority
AT 2 - Bounded function authority
The malicious overlay mediates the rendered session and user input above the operating system, providing bounded session authority without kernel, signing, or firmware-root control.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Bridges network to app overlay to device perception to user physical and decision domain.
- Reuse scale
SR 3 - Portable product-class technique
The malicious-app technique can be reused across compatible headsets, but each target must install or run the app.
- Execution scale
SX 3 - Deployment-wide with setup
The overlay can be deployed across headsets that share the required network and developer-mode setup, but it is not a zero-touch remote fleet action.
- Recovery burden
OR 3 - Coordinated operational recovery
High stealth, hard to observe once established, recoverable by configuration (disable dev mode and untrusted networks) without fleet reprovision.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. A malicious VR app can replace the rendered environment and interaction state that the wearer trusts, allowing manipulated perception to steer safety-relevant actions.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:2/CH:4/SR:3/SX:3/OR:3/EV:3/LS:MITIGATEDRead the scoring method →Privacy · Co-dominant path
Perception privacy
The malicious environment can capture live motion, gaze-related, biometric, and credential information from the headset session.
Proximity or local access
The attacker must persuade the user to install or launch the malicious VR application on the target headset.
EvidenceNo direct citation — inspect the declared inference or assumption.
Cross-domain authority chain
Captured perception and credentials are a reusable cross-domain bridge (credentials usable elsewhere).
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
The malicious environment can capture live motion, gaze-related, biometric, and credential information from the headset session.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
The malicious environment can capture live motion, gaze-related, biometric, and credential information from the headset session.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Stealthy and hard to detect, recoverable by configuration rather than fleet action.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must persuade the user to install or launch the malicious VR application on the target headset.
- Execution complexity
EC 2 - Specialist multi-step technique
The privacy path uses the same demonstrated multi-step setup as the manipulation path: local-network access, developer mode, sideloading, and a convincing overlay application.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 1 - Minor physical effect
Nuisance-level for the pure-capture consequence (no direct safety effect from observation alone).
- Data / perception
DP 4 - Safety-driving perception or intimate data
The malicious environment can capture live motion, gaze-related, biometric, and credential information from the headset session.
- Authority
AT 2 - Bounded function authority
Bounded intermediary control position above the operating system, not a trust-root or administrator and firmware authority.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Captured perception and credentials are a reusable cross-domain bridge (credentials usable elsewhere).
- Reuse scale
SR 3 - Portable product-class technique
The same application technique can be reused across compatible headsets without a device-specific secret.
- Execution scale
SX 3 - Deployment-wide with setup
Each headset requires its own app installation or launch; there is no fleet execution mechanism.
- Recovery burden
OR 3 - Coordinated operational recovery
Stealthy and hard to detect, recoverable by configuration rather than fleet action.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. The malicious environment can capture live motion, gaze-related, biometric, and credential information from the headset session.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:2/EX:2/PH:1/DP:4/AT:2/CH:4/SR:3/SX:3/OR:3/EV:3/LS:MITIGATEDRead the scoring method →Triage implication
Verify the perception transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
At least one citation still lacks a public URL; that gap keeps this record provisional.
- othersource citation pending public URL
source citation pending public URL · public URL pending
Published baseline
Keep exploit severity and consequence reasoning distinct.
No public baseline score is available for this case.
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Inception Attack: malicious VR app hijacks the entire Meta Quest environment (UChicago, 2024) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is manipulated perception that drives action.
Vulnerability
Inception Attack: malicious VR app hijacks the entire Meta Quest environment (UChicago, 2024). Reported attack vector: ADJACENT (same Wi-Fi network) plus local foothold via developer mode/sideloading.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_TO_ACTION → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:3/DP:4/AT:2/CH:4/SR:3/SX:3/OR:3/EV:3/LS:MITIGATED
Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=ELEVATED → base CRITICAL → assessed CRITICAL.
Attacker fully mediates the immersive visual/audio field (pixel-perfect cloned home + apps). The manipulated perception is the wearer’s entire reality, driving physical movement and trust decisions (e.g., altered bank-transfer amounts shown in VR browser, AI-cloned call participants). PH:3 because controlling the visual field can disorient and induce unsafe physical motion / safety-margin reduction, but no demonstrated credible injury/dangerous actuation (PH:4 reserved). RE:2 requires presence on victim Wi-Fi plus device in developer mode (adjacent/local-net, no internet-default exposure). EC:2 advanced-but-reproducible (network foothold + sideload + overlay app, demonstrated in lab). AT:2 — operates as a layer above the OS (full control of perceived session and MITM of all I/O), not kernel/root-of-trust/signing compromise, so capped at bounded-component/session authority despite breadth. DP:4 and perception_feeds_action=true: the exposed/altered world-model state (rendered reality, gaze/motion-relevant interaction) directly drives the human’s safety-relevant perception and action. CH:4, boundary_crossing=true: bridges network -> app overlay -> device perception -> user physical/decision domain. SR:3 reusable payload across Quest models tested (portable app artifact, not a shared signing key). SX:3 deployment-wide given a compromised shared network and dev-mode precondition, not fully fleet-scale remote. OR:3 high stealth, hard to observe once established, recoverable by config (disable dev mode/untrusted networks) without fleet reprovision. EV:3 reproduced by researchers.
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:2/EC:2/EX:2/PH:3/DP:4/AT:2/CH:4/SR:3/SX:3/OR:3/EV:3/LS:MITIGATED
Exposure EX=2 (reachability and complexity-bound) · bands PH=HIGH · DP=CRITICAL · AT=ELEVATED → base CRITICAL · caps privacy-only cap → assessed CRITICAL.
- Surveillance/MITM capture of all in-VR I/O: keystrokes, credentials, voice, motion, gestures, browsing, and live interactions including biometric/spatial-perception streams. DP:4 — live world-model/biometric/motion/gaze-relevant and credential data are captured; this is the headset’s perception state.
- perception_feeds_action — false here because this path is the privacy/exfiltration terminal (observe and record), distinct from the perception-manipulation->action path. PH:1 nuisance-level for the pure-capture consequence (no direct safety effect from observation alone). RE:2/EC:2 same positioning and reproducible-but-moderate-effort foothold as the manipulation path. AT:2 — bounded MITM position above the OS, not a trust-root or admin/firmware authority. CH:4 and boundary_crossing=true: captured perception/credentials are a reusable cross-domain bridge (credentials usable elsewhere). SR:3 reusable payload across tested models. SX:3 deployment-wide on a shared compromised network with dev-mode setup. OR:3 stealthy and hard to detect, recoverable by config rather than fleet action. EV:3 reproduced.
Published baseline
No public baseline score has been published for this finding. It belongs to a perception/surveillance harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.
Sources
- source citation pending public URL
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0012 (“Inception Attack: malicious VR app hijacks the entire Meta Quest environment (UChicago, 2024)”), paths.cfse.ai/CPATH-2026-0012 (published 2026-06-03).