Metaverse user worlds risk privacy through hidden surveillance hacks

Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation

Cryptography and Security

Summary

Metaverse platforms let everyday users create their own virtual worlds that others can visit and explore. The authors found that these user-created worlds can secretly spy on visitors or manipulate what they see and hear, all without needing special hacks or permissions. They showed several ways these privacy-invading tricks can be done using the standard tools available to creators. Existing platform rules and protections do not stop these hidden attacks, which means people’s privacy is at risk when using these virtual worlds.

What this means in practice

Authors

Andrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo Pellegrino

Abstract

Metaverse platforms increasingly derive their success from user-generated virtual worlds: self-contained social and interactive environments, which can be created by any ordinary user and scale to billions of visits. Platforms such as Roblox, Horizon Worlds, and VRChat now host millions of creator-built worlds that govern how users see, hear, and interact with one another. While this model enables rapid growth and creativity, it fundamentally delegates control over social interactions and world behavior to untrusted users. In this paper, we present the first systematic security and privacy assessment of metaverse world creators. We survey 25 platforms that support user-created worlds and analyze their world-creation capabilities. Guided by this analysis, we design and implement five novel attacks that exploit creator-provided tools to violate spatial, visual, and auditory constraints in immersive environments, enabling covert user surveillance and manipulation without software vulnerabilities or developer-level privileges. We further show that five previously-proposed attacks can be replicated using only standard world-creation features. Finally, we find that existing platform vetting, runtime protections, and creator policies are insufficient to mitigate malicious world-creator behavior, revealing a fundamental mismatch between users' privacy expectations and the powers granted to world creators.