Lune

USENIX Security2026Top-tier venue

Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed Reality

Mutahar Ali, Habiba Farrukh

2026Year

Abstract

Multi-user mixed reality (MR) apps create shared immersive environments where users interact through embodied avatars and virtual objects in real time. These apps are increasingly used in education, workforce training, enterprise collaboration, and social experiences. To maintain immersion, multi-user MR apps minimize latency by making clients compute and broadcast state updates, such as object tracking and interaction updates. Many apps also let users upload user-generated content, such as custom avatars and 3D assets, which is distributed to other participants. This design implicitly assumes client-side trust, where each client is expected to behave honestly: report correct state updates and upload well-formed content. However, a malicious user can exploit this trust to access information that should not be perceptually or logically available to them, inject false updates, bypass moderation and safety features, or upload malicious user-generated content. While prior work has demonstrated side-channels, perception manipulation, and privacy attacks on MR systems, the security implications of client-side trust in shared MR environments remain largely unexplored. In this paper, we present the first systematic analysis of security risks introduced by client-side trust in multi-user MR apps. We model how users and virtual objects are represented and synchronized across clients, derive security invariants that capture the conditions for safe and correct interaction, and develop a methodology to test for violations via runtime instrumentation and malicious user-generated avatars. Applying this methodology to 20 popular multi-user MR apps across different use cases and platforms, we identify five attack categories: (1) video and audio surveillance, (2) tampering of virtual objects, (3) circumvention of safety features, (4) disruption and denial-of-service, and (5) impersonation of other users. Our findings show that architectural reliance on client-side trust in multi-user MR allows a single malicious user to compromise the privacy, security, and safety of other users.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext cb5e3821-7f31-443d-8090-5c70331ebfe2

Builds on26

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines