Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation
Andrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo Pellegrino
Abstract
Metaverse platforms increasingly derive their success from usergenerated virtual worlds: self-contained social and interactive environments, which can be created by any ordinary user and scale to billions of visits. Platforms such as Roblox, Horizon Worlds, and VRChat now host millions of creator-built worlds that govern how users see, hear, and interact with one another. While this model enables rapid growth and creativity, it fundamentally delegates control over social interactions and world behavior to untrusted users. In this paper, we present the first systematic security and privacy assessment of metaverse world creators. We survey 25 platforms that support user-created worlds and analyze their world-creation capabilities. Guided by this analysis, we design and implement five novel attacks that exploit creator-provided tools to violate spatial, visual, and auditory constraints in immersive environments, enabling covert user surveillance and manipulation without software vulnerabilities or developer-level privileges. We further show that five previously-proposed attacks can be replicated using only standard world-creation features. Finally, we find that existing platform vetting, runtime protections, and creator policies are insufficient to mitigate malicious world-creator behavior, revealing a fundamental mismatch between users' privacy expectations and the powers granted to world creators.
• Security and privacy → Social aspects of security and privacy; Privacy protections.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2c42ddd0-33f1-49de-be6b-4e25d162519cBuilds on25
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- The Dark Side of Perceptual Manipulations in Virtual RealityWen-Jie Tseng, Elise Bonnail, Mark McGill, Mohamed Khamis et al.CHI 2022 · 118 citations
- Proxemics and Social Interactions in an Instrumented Virtual Reality WorkshopJulie R. Williamson, Jie Li, Vinoba Vinayagamoorthy, David A. Shamma et al.CHI 2021 · 102 citations
- Something Personal from the Metaverse: Goals, Topics, and Contextual Factors of Self-Disclosure in Commercial Social VRPhilipp Sykownik, Divine Maloney, Guo Freeman, Maic MasuchCHI 2022 · 67 citations
- Going Incognito in the Metaverse: Achieving Theoretically Optimal Privacy-Usability Tradeoffs in VRVivek C. Nair, Gonzalo Munilla Garrido, Dawn SongUIST 2023 · 54 citations
Related papers
- The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's PerspectiveAndrea Mengascini, Ryan Aurelio, Giancarlo PellegrinoCCS 2024
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
- mmSpyVR: Exploiting mmWave Radar for Penetrating Obstacles to Uncover Privacy Vulnerability of Virtual RealityLuoyu Mei, Ruofeng Liu, Zhimeng Yin, Qingchuan Zhao et al.UbiComp 2025 · 13 citations
- Digital Risks and Coping Practices among Roblox Game CreatorsQiurong Song, Rie Helene (Lindy) Hernandez, Xinning Gui, Yubo KouUSENIX Security 2026
- De-anonymization Attacks on MetaverseYan Meng, Yuxia Zhan, Jiachun Li, Suguo Du et al.INFOCOM 2023 · 13 citations
