An Empirical Study on Oculus Virtual Reality Applications: Security and Privacy Perspectives
Hanyang Guo, Hong-Ning Dai, Xiapu Luo, Zibin Zheng, Gengyang Xu, Fengliang He
Abstract
Although Virtual Reality (VR) has accelerated its prevalent adoption in emerging metaverse applications, it is not a fundamentally new technology. On one hand, most VR operating systems (OS) are based on off-the-shelf mobile OS (e.g., Android). As a result, VR apps also inherit privacy and security deficiencies from conventional mobile apps. On the other hand, in contrast to conventional mobile apps, VR apps can achieve immersive experience via diverse VR devices, such as head-mounted displays, body sensors, and controllers though achieving this requires the extensive collection of privacy-sensitive human biometrics (e.g., hand-tracking and face-tracking data). Moreover, VR apps have been typically implemented by 3D gaming engines (e.g., Unity), which also contain intrinsic security vulnerabilities. Inappropriate use of these technologies may incur privacy leaks and security vulnerabilities although these issues have not received significant attention compared to the proliferation of diverse VR apps. In this paper, we develop a security and privacy assessment tool, namely the VR-SP detector for VR apps. The VR-SP detector has integrated program static analysis tools and privacy-policy analysis methods. Using the VR-SP detector, we conduct a comprehensive empirical study on 500 popular VR apps. We obtain the original apps from the popular Oculus and SideQuest app stores and extract APK files via the Meta Oculus Quest 2 device. We evaluate security vulnerabilities and privacy data leaks of these VR apps by VR app analysis, taint analysis, and privacy-policy analysis. We find that a number of security vulnerabilities and privacy leaks widely exist in VR apps. Moreover, our results also reveal conflicting representations in the privacy policies of these apps and inconsistencies of the actual data collection with the privacy-policy statements of the apps. Based on these findings, we make suggestions for the future development of VR apps.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Motion in the Clear: Reconstructing VR User Behavior from Network TrafficJiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John et al.USENIX Security 2026
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- XRFix: Exploring Performance Bug Repair of Extended Reality Applications with Large Language ModelsJingwen Wu, Hanyang Guo, Hong-Ning Dai, Xiapu LuoICSE 2026
- From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)Kunlin Cai, Jinghuai Zhang, Ying Li, Zhiyuan Wang et al.NDSS 2026
- When VR Meets BCI: (Un)Observable Brainwave-Aware Privacy Reconstruction in the Metaverse via Unrestricted Inbuilt Motion SensorsTao Ni, Zehua Sun, Qingchuan Zhao, Wei-Bin Lee et al.S&P 2026
Builds on10
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On et al.USENIX Security 2019 · 196 citations
- An Empirical Assessment of Global COVID-19 Contact Tracing ApplicationsRuoxi Sun, Wei Wang, Minhui Xue, Gareth Tyson et al.ICSE 2021 · 54 citations
- Why Eve and Mallory Still Love Android: Revisiting TLS (In)Security in Android ApplicationsMarten Oltrogge, Nicolas Huaman, Sabrina Amft, Yasemin Acar et al.USENIX Security 2021 · 45 citations
- Contact Tracing App Privacy: What Data Is Shared By Europe's GAEN Contact Tracing AppsDouglas J. Leith, Stephen FarrellINFOCOM 2021 · 42 citations
- How Developers Optimize Virtual Reality Applications: A Study of Optimization Commits in Open Source Unity ProjectsFariha Nusrat, Foyzul Hassan, Hao Zhong, Xiaoyin WangICSE 2021 · 31 citations
Related papers
- OVRseen: Auditing Network Traffic and Privacy Policies in Oculus VRRahmadi Trimananda, Hieu Le, Hao Cui, Janice Tran Ho et al.USENIX Security 2022
- Virtual Reality, Real Problems: A Longitudinal Security Analysis of VR FirmwareVamsi Shankar Simhadri, Yichang Xiong, Habiba Farrukh, Xiaokuan ZhangCCS 2025
- AUTOVR: Automated UI Exploration for Detecting Sensitive Data Flow Exposures in Virtual Reality AppsJohn Y. Kim, Chaoshun Zuo, Yanjie Zhao, Zhiqiang LinUSENIX Security 2025
- Side-channel Inference of User Activities in AR/VR Using GPU ProfilingSeonghun Son, Chandrika Mukherjee, Reham Mohamed Aburas, Berk Gülmezoglu et al.NDSS 2026 · 4 citations
- Privacy Leakage via Unrestricted Motion-Position Sensors in the Age of Virtual Reality: A Study of Snooping Typed Input on Virtual KeyboardsYi Wu, Cong Shi, Tianfang Zhang, Payton Walker et al.S&P 2023
