homehome Home chatchat Notifications


How vulnerable are VR headsets to hacking?

From keystrokes to hand gestures, hackers can glean a lot of private information during your VR experience.

Tibi Puiu
August 9, 2023 @ 9:14 pm

share Share

Credit: Pixabay.

Virtual reality headsets are touted as gateways to a whole new experience of the digital domain, yet like all connected devices they come with an inevitable hitch — a vulnerability to hackers. A new study is raising new concerns that these headsets may be highly vulnerable to potential security breaches facilitated by their hardware and interface systems.

Case in point, computer scientists at the University of California, Riverside, have shown that VR headsets can be hacked by spyware that exploits the subtleties of our body movements to steal sensitive information and breach privacy.

Augmented reality (AR) and virtual reality (VR) are poised to become the next chapter of our internet journey, enveloping us in digital landscapes that promise experiences ranging from gaming to business interactions.

These digital dimensions rely heavily on headsets that translate our physical gestures into navigational cues—turning, nodding, stepping, and blinking guide us through these parallel universes. Oculus Quest, for example, also supports voice dictation for entering web addresses, controlling the headset, and exploring commercial products. However, researchers have found that this interplay of technology leaves a back door open for potential hackers.

Researchers led by Jiasi Chen and Nael Abu-Ghazaleh revealed how malicious actors can exploit the unique interactions facilitated by these headsets. Using spyware and advanced artificial intelligence, they can covertly monitor and record users’ gestures, translating these subtle movements into words with an astonishing accuracy of 90% or higher. Hackers could potentially accurately estimate the proximity of nearby individuals within a margin of just about 4 inches (10.3 cm).

“In essence, our findings indicate that if one of the applications is compromised, it can covertly surveil other applications,” explains Abu-Ghazaleh. “This includes monitoring your surroundings, detecting the presence of people nearby and their distance, as well as uncovering your interactions within the virtual environment.”

The implications of these vulnerabilities are startling. Imagine taking a pause from an engrossing virtual game to check your Facebook messages using a virtual keyboard. The spyware could stealthily capture your keystrokes, potentially compromising sensitive information. Similarly, during a virtual meeting where confidential data is shared, the minutiae of your body movements could inadvertently leak crucial information to prying eyes.

For instance, hackers could use TyPose, a system leveraging machine learning to decipher head motion signals and automatically decipher the words or characters users are inputting. That’s quite concerning, which is why the researchers hope that their ethical hacking experiment may serve as a clarion call to the tech industry, which will hopefully work to patch these vulnerabilities.

Meta, the company behind Facebook but also Metaverse headsets like the Oculus Quest, is offering bounties of up to $300,000 to ethical hackers who can find vulnerabilities that could allow an attacker to execute malware or take control of a device.

“Our intention is to showcase the potential for attacks, and then provide the companies with a window to address these vulnerabilities before we make our findings public,” Abu-Ghazaleh asserts in a media statement.

The findings appeared in two papers (1 and 2) that were presented this week at the annual Usenix Security Symposium in Anaheim.

share Share

The World's Tiniest Pacemaker is Smaller Than a Grain of Rice. It's Injected with a Syringe and Works using Light

This new pacemaker is so small doctors could inject it directly into your heart.

Scientists Just Made Cement 17x Tougher — By Looking at Seashells

Cement is a carbon monster — but scientists are taking a cue from seashells to make it tougher, safer, and greener.

Three Secret Russian Satellites Moved Strangely in Orbit and Then Dropped an Unidentified Object

We may be witnessing a glimpse into space warfare.

Researchers Say They’ve Solved One of the Most Annoying Flaws in AI Art

A new method that could finally fix the bizarre distortions in AI-generated images when they're anything but square.

The small town in Germany where both the car and the bicycle were invented

In the quiet German town of Mannheim, two radical inventions—the bicycle and the automobile—took their first wobbly rides and forever changed how the world moves.

Scientists Created a Chymeric Mouse Using Billion-Year-Old Genes That Predate Animals

A mouse was born using prehistoric genes and the results could transform regenerative medicine.

Americans Will Spend 6.5 Billion Hours on Filing Taxes This Year and It’s Costing Them Big

The hidden cost of filing taxes is worse than you think.

Underwater Tool Use: These Rainbow-Colored Fish Smash Shells With Rocks

Wrasse fish crack open shells with rocks in behavior once thought exclusive to mammals and birds.

This strange rock on Mars is forcing us to rethink the Red Planet’s history

A strange rock covered in tiny spheres may hold secrets to Mars’ watery — or fiery — past.

Scientists Found a 380-Million-Year-Old Trick in Velvet Worm Slime That Could Lead To Recyclable Bioplastic

Velvet worm slime could offer a solution to our plastic waste problem.