Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Privacy · Dominant path
Perception privacy
Leaks live speech content from sensors users never perceive as a microphone.
Reusable artifact or reachable service
A zero-permission application on the headset can sample the motion sensor without prompting the user.
EvidenceNo direct citation — inspect the declared inference or assumption.
One cross-boundary bridge
Enables further inference but not a reusable cross-domain authority bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Leaks live speech content from sensors users never perceive as a microphone.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception privacy
Leaks live speech content from sensors users never perceive as a microphone.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Largely unpatchable since sensors are core to head tracking, recovery requires hardware and platform-level change; fleet-wide recovery is required.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 3 - Reusable artifact or reachable service
A zero-permission application on the headset can sample the motion sensor without prompting the user.
- Execution complexity
EC 3 - Reproducible exploit workflow
Standard ML researcher workflow (sensor capture and deep-learning pipeline).
- Exposure
EX 3 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 0 - No direct physical effect
The inferred speech exposes private conversation but does not directly drive a physical or safety decision.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Leaks live speech content from sensors users never perceive as a microphone.
- Authority
AT 1 - Read-only or preparatory access
The exploited surface is the absence of a permission gate, not elevated privilege, exploiting a read-only sensor feature.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
Enables further inference but not a reusable cross-domain authority bridge.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The inference technique can be reused across compatible headsets because it does not depend on a device-specific secret.
- Execution scale
SX 3 - Deployment-wide with setup
Each headset must run the sampling application and process its own sensor stream.
- Recovery burden
OR 4 - Fleet action or replacement
Largely unpatchable since sensors are core to head tracking, recovery requires hardware and platform-level change; fleet-wide recovery is required.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Leaks live speech content from sensors users never perceive as a microphone.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →Privacy · Supporting path
Data privacy
Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.
Reusable artifact or reachable service
A zero-permission application on the headset can sample the motion sensor without prompting the user.
EvidenceNo direct citation — inspect the declared inference or assumption.
One cross-boundary bridge
Biometric identity could feed deanonymization but is not a reusable authority-transfer bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Unpatchable sensor-design property, recovery needs platform and hardware change; fleet-wide recovery is required.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 3 - Reusable artifact or reachable service
A zero-permission application on the headset can sample the motion sensor without prompting the user.
- Execution complexity
EC 3 - Reproducible exploit workflow
Inferring speaker identity from motion-sensor traces requires the demonstrated machine-learning pipeline and trained classifier.
- Exposure
EX 3 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 0 - No direct physical effect
The recovered speech content creates a privacy consequence without directly changing physical behavior.
- Data / perception
DP 3 - Sensitive device or personal data
Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.
- Authority
AT 1 - Read-only or preparatory access
Absence of permission gate on a read-only sensor, no elevated privilege.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
Biometric identity could feed deanonymization but is not a reusable authority-transfer bridge.
- Reuse scale
SR 4 - Shared fleet-wide primitive
One reusable model across mainstream headsets exploiting a shared design flaw.
- Execution scale
SX 3 - Deployment-wide with setup
Each headset must run the sampling application and process its own sensor stream.
- Recovery burden
OR 4 - Fleet action or replacement
Unpatchable sensor-design property, recovery needs platform and hardware change; fleet-wide recovery is required.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. Motion-sensor inference can reveal speaker identity and other persistent biometric attributes in addition to reconstructing speech content.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →Triage implication
Verify the privacy transition before acting on the band.
Protect the outward data or sensor boundary and verify what sensitive behavior can be reconstructed, not only what raw fields are exposed.
Evidence ledger
Public sources used by this record.
At least one citation still lacks a public URL; that gap keeps this record provisional.
- othersource citation pending public URL
source citation pending public URL · public URL pending
Published baseline
Keep exploit severity and consequence reasoning distinct.
No public baseline score is available for this case.
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.
Vulnerability
Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021). Reported attack vector: LOCAL (malicious or sandboxed app reading zero-permission sensors on-device).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE
Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.
- Position: any installed/sandboxed app or web content reads zero-permission motion sensors using its own artifact, no victim physical access -> RE:3. EC:3 standard ML researcher workflow (sensor capture + deep-learning pipeline). The exploited surface is the absence of a permission gate, not elevated privilege, exploiting a read-only sensor feature -> AT:1. PH:0 no actuation/safety, pure side-channel privacy leak. DP:4: leaks live speech content from sensors users never perceive as a microphone;
- perception_feeds_action — false since the leaked perception does not drive physical action/navigation/therapy.
- boundary_crossing — true: app sandbox -> on-device sensor -> physical acoustic side-channel -> exfiltrated content. CH:2 enables further inference but not a reusable cross-domain authority bridge. SR:4: one model/technique reused across the fleet, exploiting a shared design property of mainstream headsets. SX:3: deployment-wide via app distribution but still per-device install/run, not pure remote fleet command. OR:4: largely unpatchable since sensors are core to head tracking, recovery requires hardware/platform-level change -> recovery_needs_fleet_action=true. EV:3 reproduced in CCS 2021.
- active_exploitation — false (research demonstration, no wild exploitation evidence).
DATA_PRIVACY → HIGH
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE
Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery · caps privacy-only cap → assessed HIGH.
- Same access path: zero-permission sensor read via attacker’s own app artifact -> RE:3, EC:3 standard ML workflow. AT:1 absence of permission gate on a read-only sensor, no elevated privilege. PH:0 no actuation/safety impact. Terminal consequence here is biometric identity/gender inference (speaker identity), a persistent biometric/sensitive attribute leak -> DP:3 (health/credential/biometric tier);
- perception_feeds_action — false.
- boundary_crossing — true across app/sensor/physical side-channel. CH:2 biometric identity could feed deanonymization but is not a reusable authority-transfer bridge. SR:4 one reusable model across mainstream headsets exploiting a shared design flaw. SX:3 deployment-wide via app distribution, per-device install. OR:4 unpatchable sensor-design property, recovery needs platform/hardware change -> recovery_needs_fleet_action=true. EV:3 reproduced.
- active_exploitation — false.
Published baseline
No public baseline score has been published for this finding. It belongs to a perception/surveillance harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.
Sources
- source citation pending public URL
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0016 (“Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)”), paths.cfse.ai/CPATH-2026-0016 (published 2026-06-03).