The Big Brother's New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User's Perspective
Andrea Mengascini, Ryan Aurelio, Giancarlo Pellegrino
摘要
Metaverses are virtual worlds where users can engage in social exchanges, collaborate, or play games. Their clients now are JavaScript programs that run inside modern web browsers. They implement functionalities typical of multiplayer video games, like 3D and physics engines, requiring them to maintain complex data structures of objects in the browser's memory. Unfortunately, these objects can be accessed and manipulated by malicious users, allowing them to learn about events beyond the ones rendered on screen or to hijack the physics of the metaverse to spy on other users. In this paper, we propose one of the first comprehensive security assessments for web clients of metaverse platforms. We begin with a survey and selection of three metaverse platforms and introduce a software-centric threat modeling approach designed to identify the security-relevant entities. Then, we propose a JavaScript global object snapshot diffing technique to identify in-memory objects correlated with the attribute and design 10 attacks, of which eight successfully executed against at least one of the metaverses, enabling a malicious user to perform audio/video surveillance or continuous user position tracking -to mention a few -who could exacerbate current threats posed by stalkers and online abusers. Finally, we discuss the implications of our attacks should the metaverse become a business tool and possible solutions. CCS Concepts • Security and privacy → Web application security; Domainspecific security and privacy architectures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- Relay and Betray: Exploiting Client-Side Authority in Multi-User Mixed RealityMutahar Ali, Habiba FarrukhUSENIX Security 2026
它引用的顶会 Paper8
- Fidelius: Protecting User Secrets from Compromised BrowsersSaba Eskandarian, Jonathan Cogan, Sawyer Birnbaum, Peh Chang Wei Brandon 等S&P 2019 · 被引用 55 次
- Combining Real-World Constraints on User Behavior with Deep Neural Networks for Virtual Reality (VR) BiometricsRobert Miller, Natasha Kholgade Banerjee, Sean BanerjeeIEEE VR 2022 · 被引用 41 次
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 等USENIX Security 2024 · 被引用 29 次
- That Doesn't Go There: Attacks on Shared State in Multi-User Augmented Reality ApplicationsCarter Slocum, Yicheng Zhang, Erfan Shayegani, Pedram Zaree 等USENIX Security 2024 · 被引用 21 次
- BlackMirror: Preventing Wallhacks in 3D Online FPS GamesSeonghyun Park, Adil Ahmad, Byoungyoung LeeCCS 2020 · 被引用 17 次
相关 Paper
- Detecting and understanding JavaScript global identifier conflicts on the webMingxue Zhang, Wei MengFSE 2020 · 被引用 10 次
- It's (DOM) Clobbering Time: Attack Techniques, Prevalence, and DefensesSoheil Khodayari, Giancarlo PellegrinoS&P 2023
- Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3Christof Ferreira Torres, Fiona Willi, Shweta ShindeUSENIX Security 2023
- Deterministic BrowserYinzhi Cao, Zhanhao Chen, Song Li, Shujiang WuCCS 2017 · 被引用 32 次
- JavaScript Zero: Real JavaScript and Zero Side-Channel AttacksMichael Schwarz, Moritz Lipp, Daniel GrussNDSS 2018 · 被引用 67 次
