The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's Perspective
Andrea Mengascini, Ryan Aurelio, Giancarlo Pellegrino
Abstract
Metaverses are virtual worlds where users can engage in social exchanges, collaborate, or play games. Their clients now are JavaScript programs that run inside modern web browsers. They implement functionalities typical of multiplayer video games, like 3D and physics engines, requiring them to maintain complex data structures of objects in the browser's memory. Unfortunately, these objects can be accessed and manipulated by malicious users, allowing them to learn about events beyond the ones rendered on screen or to hijack the physics of the metaverse to spy on other users. In this paper, we propose one of the first comprehensive security assessments for web clients of metaverse platforms. We begin with a survey and selection of three metaverse platforms and introduce a software-centric threat modeling approach designed to identify the security-relevant entities. Then, we propose a JavaScript global object snapshot diffing technique to identify in-memory objects correlated with the attribute and design 10 attacks, of which eight successfully executed against at least one of the metaverses, enabling a malicious user to perform audio/video surveillance or continuous user position tracking -to mention a few -who could exacerbate current threats posed by stalkers and online abusers. Finally, we discuss the implications of our attacks should the metaverse become a business tool and possible solutions. CCS Concepts • Security and privacy → Web application security; Domainspecific security and privacy architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cbc12106-9b3d-4b2e-9d95-0fcdf75ece5bCited by top-tier papers2
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
Builds on8
- Fidelius: Protecting User Secrets from Compromised BrowsersSaba Eskandarian, Jonathan Cogan, Sawyer Birnbaum, Peh Chang Wei Brandon et al.S&P 2019 · 55 citations
- Combining Real-World Constraints on User Behavior with Deep Neural Networks for Virtual Reality (VR) BiometricsRobert Miller, Natasha Kholgade Banerjee, Sean BanerjeeIEEE VR 2022 · 41 citations
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree et al.USENIX Security 2024 · 21 citations
- BlackMirror: Preventing Wallhacks in 3D Online FPS GamesSeonghyun Park, Adil Ahmad, Byoungyoung LeeCCS 2020 · 17 citations
Related papers
- Detecting and understanding JavaScript global identifier conflicts on the webMingxue Zhang, Wei MengFSE 2020 · 10 citations
- It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and DefensesSoheil Khodayari, Giancarlo PellegrinoS&P 2023
- Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3Christof Ferreira Torres, Fiona Willi, Shweta ShindeUSENIX Security 2023
- Deterministic BrowserYinzhi Cao, Zhanhao Chen, Song Li, Shujiang WuCCS 2017 · 32 citations
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 67 citations
