
9/12/2023 · Andrew Calvano, Adrian Tolbaru
What this post added
This post details the discovery and exploitation of a memory corruption vulnerability in Meta Quest 2's VR Runtime service. The vulnerability, triggered by an unprivileged application via Runtime IPC, allowed for arbitrary 8-byte corruptions at arbitrary offsets within a statically-sized array. The exploit chain successfully turned this into arbitrary native code execution by overwriting a function pointer within the Vulkan loader, demonstrating a method to escalate privileges on the device and informing security improvements for Meta Quest products.