Metaverse user worlds risk privacy through hidden surveillance hacks
Omniscience for the Masses: New Threats in the Metaverse's Democratized World Creation
Cryptography and Security
Summary
Metaverse platforms let everyday users create their own virtual worlds that others can visit and explore. The authors found that these user-created worlds can secretly spy on visitors or manipulate what they see and hear, all without needing special hacks or permissions. They showed several ways these privacy-invading tricks can be done using the standard tools available to creators. Existing platform rules and protections do not stop these hidden attacks, which means people’s privacy is at risk when using these virtual worlds.
What this means in practice
- •For metaverse platform engineers: Identify and patch security gaps in user-created worlds to prevent covert surveillance and manipulation.
- •For privacy compliance teams: Design better vetting and runtime monitoring policies to address privacy risks from user-built virtual environments.
Authors
Andrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo Pellegrino
Abstract
Metaverse platforms increasingly derive their success from user-generated virtual worlds: self-contained social and interactive environments, which can be created by any ordinary user and scale to billions of visits. Platforms such as Roblox, Horizon Worlds, and VRChat now host millions of creator-built worlds that govern how users see, hear, and interact with one another. While this model enables rapid growth and creativity, it fundamentally delegates control over social interactions and world behavior to untrusted users. In this paper, we present the first systematic security and privacy assessment of metaverse world creators. We survey 25 platforms that support user-created worlds and analyze their world-creation capabilities. Guided by this analysis, we design and implement five novel attacks that exploit creator-provided tools to violate spatial, visual, and auditory constraints in immersive environments, enabling covert user surveillance and manipulation without software vulnerabilities or developer-level privileges. We further show that five previously-proposed attacks can be replicated using only standard world-creation features. Finally, we find that existing platform vetting, runtime protections, and creator policies are insufficient to mitigate malicious world-creator behavior, revealing a fundamental mismatch between users' privacy expectations and the powers granted to world creators.