perception
PERCEPTION_PRIVACY
Vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE CPATH-2026-0016 · SMART GLASSES AR
PERCEPTION_PRIVACY perception · Evidence EV:3 (reproduced / report-backed) · Liveness ACTIVE | CPATH ID | CPATH-2026-0016 |
| CVE(s) | — |
| Device / class | Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) (SMART GLASSES AR) |
| Vendor | Meta |
| Dominant consequence | PERCEPTION_PRIVACY (perception) |
| Paths verdict | CRITICAL (worst of 2 paths) |
| Published baseline | No public baseline score is published for this case. The registry still records the reachable consequence path for review. |
| Baseline relationship | ⊘ no published baseline |
| Consequence dimension(s) | #1 #2 #7 #8 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | low |
Consequence Paths
perception
PERCEPTION_PRIVACYCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE perception
DATA_PRIVACYCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE CFSE Consequence Paths assesses Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.
Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021). Reported attack vector: LOCAL (malicious or sandboxed app reading zero-permission sensors on-device).
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_PRIVACY → CRITICALCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE
Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.
DATA_PRIVACY → HIGHCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE
Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery · caps privacy-only cap → assessed HIGH.
No public baseline score has been published for this finding. It belongs to a perception/surveillance harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0016 (“Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)”), paths.cfse.ai/CPATH-2026-0016 (published 2026-06-03).