← Registry

CPATH-2026-0016 · SMART GLASSES AR

Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence PERCEPTION_PRIVACY perception · Evidence EV:3 (reproduced / report-backed) · Liveness ACTIVE
CPATH IDCPATH-2026-0016
CVE(s)
Device / classFace-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) (SMART GLASSES AR)
VendorMeta
Dominant consequencePERCEPTION_PRIVACY (perception)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline No public baseline score is published for this case. The registry still records the reachable consequence path for review.
Baseline relationship⊘ no published baseline
Consequence dimension(s)#1 #2 #7 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencelow
Citation review open. One or more source labels do not yet include public links. Treat those facts as needing citation review before relying on them.

Consequence Paths

Paths Assessment

perception

PERCEPTION_PRIVACY

CRITICAL
Reachability RE:3
Complexity EC:3
Consequence PERCEPTION_PRIVACY
Scale SR:4 / SX:3
Verdict CRITICAL
Reachability 3
Complexity 3
Exposure 3
Physical / safety 0
Data / perception 4
Authority 1
Chainability 2
Reuse scale 4
Execution scale 3
Recovery 4
Evidence EV:3 · reproduced / report-backed
Liveness ACTIVE
Vector CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

perception

DATA_PRIVACY

HIGH
Reachability RE:3
Complexity EC:3
Consequence DATA_PRIVACY
Scale SR:4 / SX:3
Verdict HIGH
Reachability 3
Complexity 3
Exposure 3
Physical / safety 0
Data / perception 3
Authority 1
Chainability 2
Reuse scale 4
Execution scale 3
Recovery 4
Evidence EV:3 · reproduced / report-backed
Liveness ACTIVE
Vector CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

Assessment

CFSE Consequence Paths assesses Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021) at CRITICAL — the worst of 2 risk paths (perception). The dominant consequence is exposure of sensor or biometric data.

Vulnerability

Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021). Reported attack vector: LOCAL (malicious or sandboxed app reading zero-permission sensors on-device).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:4/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=CRITICAL · AT=HIGH → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:3/EC:3/EX:3/PH:0/DP:3/AT:1/CH:2/SR:4/SX:3/OR:4/EV:3/LS:ACTIVE

Exposure EX=3 (reachability and complexity-bound) · bands PH=ELEVATED · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery · caps privacy-only cap → assessed HIGH.

Published baseline

No public baseline score has been published for this finding. It belongs to a perception/surveillance harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0016 (“Face-Mic: zero-permission motion-sensor speech and speaker-identity eavesdropping on AR/VR headsets (Rutgers/NJIT, 2021)”), paths.cfse.ai/CPATH-2026-0016 (published 2026-06-03).