CVE-2026-92173
CVE-2026-92173 is a critical-severity vulnerability with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-923.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-923
- Published:
- Last modified:
Description
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
Frequently asked questions
- What is CVE-2026-92173?
- Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as well as packages signed with the same key, towards any endpoint within the OS that uses CallerIdentity authentication.
- How severe is CVE-2026-92173?
- CVE-2026-92173 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-92173 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-92173?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-92173 published?
- CVE-2026-92173 was published on 2026-09-30 and last updated on 2026-10-01.
References
Other CWE-923 vulnerabilities
- CVE-2019-17440 — Critical (CVSS 10.0): Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation…
- CVE-2024-41889 — Critical (CVSS 9.8): Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited,…
- CVE-2026-34205 — Critical (CVSS 9.6): Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps…
- CVE-2023-28078 — Critical (CVSS 9.1): Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A…
- CVE-2026-86345 — Critical (CVSS 9.0): A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection…
- CVE-2026-92172 — High (CVSS 8.8): Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent…