CPATH-2026-0016 · Smart glasses / AR

Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)

A dominant perception privacy path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathPerception privacy

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Privacy · Dominant path

Perception privacy

Leaks live speech content from sensors users never perceive as a microphone.

CRITICAL
  1. accessModel inference

    Reusable artifact or reachable service

    A zero-permission application on the headset can sample the motion sensor without prompting the user.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  2. boundaryModel inference

    One cross-boundary bridge

    Enables further inference but not a reusable cross-domain authority bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Leaks live speech content from sensors users never perceive as a microphone.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception privacy

    Leaks live speech content from sensors users never perceive as a microphone.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Largely unpatchable since sensors are core to head tracking, recovery requires hardware and platform-level change; fleet-wide recovery is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

A zero-permission application on the headset can sample the motion sensor without prompting the user.

Model inference
Execution complexityEC 3
Reproducible exploit workflow

Standard ML researcher workflow (sensor capture and deep-learning pipeline).

Model inference
ExposureEX 3
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

The inferred speech exposes private conversation but does not directly drive a physical or safety decision.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Leaks live speech content from sensors users never perceive as a microphone.

Model inference
AuthorityAT 1
Read-only or preparatory access

The exploited surface is the absence of a permission gate, not elevated privilege, exploiting a read-only sensor feature.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Enables further inference but not a reusable cross-domain authority bridge.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The inference technique can be reused across compatible headsets because it does not depend on a device-specific secret.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Each headset must run the sampling application and process its own sensor stream.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Largely unpatchable since sensors are core to head tracking, recovery requires hardware and platform-level change; fleet-wide recovery is required.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Model inference
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Operational assumption

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Leaks live speech content from sensors users never perceive as a microphone.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →

Privacy · Supporting path

Data privacy

Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.

HIGH
  1. accessModel inference

    Reusable artifact or reachable service

    A zero-permission application on the headset can sample the motion sensor without prompting the user.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  2. boundaryModel inference

    One cross-boundary bridge

    Biometric identity could feed deanonymization but is not a reusable authority-transfer bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Unpatchable sensor-design property, recovery needs platform and hardware change; fleet-wide recovery is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

A zero-permission application on the headset can sample the motion sensor without prompting the user.

Model inference
Execution complexityEC 3
Reproducible exploit workflow

Inferring speaker identity from motion-sensor traces requires the demonstrated machine-learning pipeline and trained classifier.

Model inference
ExposureEX 3
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

The recovered speech content creates a privacy consequence without directly changing physical behavior.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.

Model inference
AuthorityAT 1
Read-only or preparatory access

Absence of permission gate on a read-only sensor, no elevated privilege.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Biometric identity could feed deanonymization but is not a reusable authority-transfer bridge.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One reusable model across mainstream headsets exploiting a shared design flaw.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Each headset must run the sampling application and process its own sensor stream.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Unpatchable sensor-design property, recovery needs platform and hardware change; fleet-wide recovery is required.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Model inference
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Operational assumption

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →

Triage implication

Verify the privacy transition before acting on the band.

Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.

Evidence ledger

Public sources used by this record.

At least one citation still lacks a public URL; that gap keeps this record provisional.

  • other
    source citation pending public URL

    source citation pending public URL · public URL pending

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipNo comparable score
Baseline confidencelow
Scored2026-06-03

No public baseline score is available for this case.

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.

Vulnerability

Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021). Reported attack vector: LOCAL (malicious or sandboxed app reading zero-permission sensors on-device).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.

  • Position: any installed/sandboxed app or web content reads zero-permission motion sensors using its own artifact, no victim physical access -> RE:3. EC:3 standard ML researcher workflow (sensor capture + deep-learning pipeline). The exploited surface is the absence of a permission gate, not elevated privilege, exploiting a read-only sensor feature -> AT:1. PH:0 no actuation/safety, pure side-channel privacy leak. DP:4: leaks live speech content from sensors users never perceive as a microphone;
  • perception_feeds_action — false since the leaked perception does not drive physical action/navigation/therapy.
  • boundary_crossing — true: app sandbox -> on-device sensor -> physical acoustic side-channel -> exfiltrated content. CH:2 enables further inference but not a reusable cross-domain authority bridge. SR:4: one model/technique reused across the fleet, exploiting a shared design property of mainstream headsets. SX:3: deployment-wide via app distribution but still per-device install/run, not pure remote fleet command. OR:4: largely unpatchable since sensors are core to head tracking, recovery requires hardware/platform-level change -> recovery_needs_fleet_action=true. EV:3 reproduced in CCS 2021.
  • active_exploitation — false (research demonstration, no wild exploitation evidence).

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery · caps privacy-only cap → assessed HIGH.

  • Same access path: zero-permission sensor read via attacker’s own app artifact -> RE:3, EC:3 standard ML workflow. AT:1 absence of permission gate on a read-only sensor, no elevated privilege. PH:0 no actuation/safety impact. Terminal consequence here is biometric identity/gender inference (speaker identity), a persistent biometric/sensitive attribute leak -> DP:3 (health/credential/biometric tier);
  • perception_feeds_action — false.
  • boundary_crossing — true across app/sensor/physical side-channel. CH:2 biometric identity could feed deanonymization but is not a reusable authority-transfer bridge. SR:4 one reusable model across mainstream headsets exploiting a shared design flaw. SX:3 deployment-wide via app distribution, per-device install. OR:4 unpatchable sensor-design property, recovery needs platform/hardware change -> recovery_needs_fleet_action=true. EV:3 reproduced.
  • active_exploitation — false.

Published baseline

No public baseline score has been published for this finding. It belongs to a perception/surveillance harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.

Sources

  • source citation pending public URL

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0016 (“Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)”), paths.cfse.ai/CPATH-2026-0016 (published 2026-06-03).