{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-92172",
        "assignerOrgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
        "state": "PUBLISHED",
        "assignerShortName": "Meta",
        "dateReserved": "2026-09-15T17:32:03.673Z",
        "datePublished": "2026-09-30T20:26:49.629Z",
        "dateUpdated": "2026-09-30T20:26:49.629Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Meta Horizon OS",
                    "vendor": "Meta Platforms, Inc",
                    "versions": [
                        {
                            "lessThan": "v66.0.0.733.524",
                            "status": "affected",
                            "version": "v0.0.0.0.0",
                            "versionType": "semver"
                        }
                    ]
                }
            ],
            "dateAssigned": "2026-09-15T00:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering for com.oculus.systemactivities.SCREENSHOT via a broadcast receiver. That would allow the application to impersonate the com.oculus.horizon package towards any endpoint within the OS that uses CallerIdentity authentication."
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "description": "Improper Restriction of Communication Channel to Intended Endpoints (CWE-923)",
                            "lang": "en"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "4fc57720-52fe-4431-a0fb-3d2c8747b827",
                "shortName": "Meta",
                "dateUpdated": "2026-09-30T20:26:49.629Z"
            },
            "references": [
                {
                    "tags": [
                        "x_refsource_CONFIRM"
                    ],
                    "url": "https://www.facebook.com/security/advisories/cve-2026-92172"
                }
            ]
        }
    }
}