Pith. sign in

REVIEW 2 cited by

Virtual Reality and Augmented Reality Security: A Reconnaissance and Vulnerability Assessment Approach

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.15984 v1 pith:F3EQ7D5F submitted 2024-07-22 cs.CR

classification cs.CR
keywords realitysecurityvulnerabilitiesassessmentattacksphasereconnaissancetechnologies
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Various industries have widely adopted Virtual Reality (VR) and Augmented Reality (AR) technologies to enhance productivity and user experiences. However, their integration introduces significant security challenges. This systematic literature review focuses on identifying devices used in AR and VR technologies and specifies the associated vulnerabilities, particularly during the reconnaissance phase and vulnerability assessment, which are critical steps in penetration testing. Following Kitchenham and Charters' guidelines, we systematically selected and analyzed primary studies. The reconnaissance phase involves gathering detailed information about AR and VR systems to identify potential attack vectors. In the vulnerability assessment phase, these vectors are analyzed to pinpoint weaknesses that malicious actors could exploit. Our findings reveal that AR and VR devices, such as headsets (e.g., HTC Vive, Oculus Quest), development platforms (e.g., Unity Framework, Google Cardboard SDK), and applications (e.g., Bigscreen VR, VRChat), are susceptible to various attacks, including remote code execution, cross-site scripting (XSS), eavesdropping, and man-in-the-room attacks. Specifically, the Bigscreen VR application exhibited severe vulnerabilities like remote code execution (RCE) via the 'Application.OpenURL' API, XSS in user inputs, and botnet propagation. Similarly, the Oculus Quest demonstrated susceptibility to side-channel attacks and ransomware. This paper provides a detailed overview of specific device vulnerabilities and emphasizes the importance of the initial steps in penetration testing to identify security weaknesses in AR and VR systems. By highlighting these vulnerabilities, we aim to assist researchers in exploring and mitigating these security challenges, ensuring the safe deployment and use of AR and VR technologies across various sectors.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)

    cs.CR 2025-09 conditional novelty 6.0 of 10

    A 23-developer interview study shows professional XR developers recall few XR-specific threats unprompted, rate unfamiliar attacks lower, and exhibit awareness gaps plus diffusion of responsibility.

  2. NRXR-ID: Two-Factor Authentication (2FA) in VR Using Near-Range Extended Reality and Smartphones

    cs.HC 2025-07 conditional novelty 6.0 of 10

    In a 4x3 user study (N=30), a checkers-style visual matching challenge and a six-digit PIN were the most preferred and effective 2FA methods when using a smartphone seen via near-range pass-through in VR.

Pith tools