Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Vivo X300 Ultra Launch in India Confirmed: Check Full Specifications and Expected Price

    April 17, 2026

    OPPO F33 And F33 Pro Launched In India With 7,000mAh Battery, Dimensity 6360 Max: Check Price And Specs

    April 17, 2026

    Motorola Edge 70 Pro Launch Date in India and Full Specifications Confirmed Through Flipkart

    April 17, 2026
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Hummer EV Price in India 2026: Complete Guide, Features, Specifications & Availability

      April 2, 2026

      Apple Vision Pro vs Meta Quest 3: The Ultimate VR Headset Showdown

      December 3, 2025

      ChatGPT told them they were special — their families say it led to tragedy

      November 24, 2025

      Beehiiv’s CEO isn’t worried about newsletter saturation

      November 24, 2025

      TechCrunch Mobility: Searching for the robotaxi tipping point

      November 24, 2025
    • Mobiles

      Vivo X300 Ultra Launch in India Confirmed: Check Full Specifications and Expected Price

      April 17, 2026

      OPPO F33 And F33 Pro Launched In India With 7,000mAh Battery, Dimensity 6360 Max: Check Price And Specs

      April 17, 2026

      Motorola Edge 70 Pro Launch Date in India and Full Specifications Confirmed Through Flipkart

      April 17, 2026

      Moto Pad 60 Pro and Moto Pad 60 Neo Get a Price Hike in India: Check New Prices

      April 16, 2026

      OPPO Reno 16 Pro Full Specifications and Colourways Revealed: Check Launch Timeline for the Reno 16 Series

      April 16, 2026
    • Gaming

      Roblox’s AI assistant gets new agentic tools to plan, build, and test games

      April 17, 2026

      How the rewards app Freecash scammed its way to the top of the app stores

      April 15, 2026

      Where Baldur’s Gate 3 Gets Player Agency vs. Narrative Control Right (and Wrong)

      April 14, 2026

      Best Fallout 4 Romance Mods

      April 14, 2026

      Scratch & Peek

      April 14, 2026
    • SEO Tips
    • PC/ Laptops

      Dell Pro 14 (AMD Ryzen AI 7 Pro 350) Review: The Sensible Choice for Everyday Office Work

      January 9, 2026

      CES 2026: MSI Unveils New Prestige, Raider, Stealth and Crosshair Laptops with Intel Core Ultra SoCs

      January 7, 2026

      CES 2026: Samsung Unveils New Galaxy Book6 Laptops

      January 6, 2026

      CES 2026: HP Shows a Keyboard-Based PC and New EliteBooks

      January 6, 2026

      CES 2026: Intel Unveils Core Ultra Series 3, Its First Platform Built on 18A

      January 6, 2026
    • EV

      Hummer EV Price in India 2026: Complete Guide, Features, Specifications & Availability

      April 2, 2026

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Editor's Choice - Study reveals vulnerability of metaverse platforms to cyber attacks
    Editor's Choice

    Study reveals vulnerability of metaverse platforms to cyber attacks

    KavishBy KavishDecember 13, 2024No Comments7 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Study reveals vulnerability of metaverse platforms to cyber attacks
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Study reveals vulnerability of metaverse platforms to cyber attacks
    Visualization to the paper “The Big Brother’s New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User’s Perspective” Credit: CISPA

    Having access to virtual worlds from your home computer via your web browser and being able to interact with others in a secure and private manner: that is the promise of metaverse platforms.

    CISPA researcher Andrea Mengascini conducted a reality check on this promise and discovered significant risks in terms of a lack of privacy and the danger of cyberattacks. He presented his study, “The Big Brother’s New Playground. Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User’s Perspective,” at the Conference on Computer and Communications Security (CCS) in fall 2024.

    “I’ve always been interested in virtual reality and online games,” CISPA researcher Andrea Mengascini said. When he and his research group leader, CISPA-Faculty Dr. Giancarlo Pellegrino, started investigating the safety of VR headsets, they discovered something interesting: “We realized that it was the same technology used in online games that is also used in metaverses,” says Mengascini.

    He defines a metaverse as a “virtual social space in which people can interact according to rules that in some way mirror the rules of the physical world.” While the security of online games has been researched and defenses have been implemented, it was still an open question with regard to metaverse platforms. This is what caught Mengascini’s interest.

    “Accessing a metaverse has become much easier in recent years,” explains Mengascini. “Today, all you need is a normal web browser to enter these rooms. Thanks to the WebXR API interface, it is also possible to use a VR headset.”

    In the Metaverse, people find a kind of digital copy of the real world: there are rooms for private meetings, large or small public events, fun and entertainment.

    “These platforms run as web-based clients and use JavaScript to manage complex 3D environments, the avatars of users and real-time interactions. All of this is not only crucial for the smooth operation of the Metaverse, but also plays a major role in its security,” says the researcher. Mengascini’s goal was to find out if there are any security gaps when accessing the Metaverse via web browsers.

    Table of Contents

    Toggle
    • The researcher’s questions and approach
    • Memories are easy to access
    • Potential attack scenarios
    • New research questions to take away

    The researcher’s questions and approach

    For his study, Mengascini posed three specific questions:

    1. Which entities, such as users and objects, exist in metaverses and which attributes, such as position, appearance, etc., are assigned to them?
    2. Where exactly are these elements stored in the memory, and what access can attackers gain to this memory?
    3. How can the memory be exploited for attacks?

    Via a Google search, the CISPA researcher first identified 27 metaverse platforms that use the WebXR API interface. In a next step, he examined three of them in more detail, as they performed best in terms of popularity, user activity, internet traffic and coverage of real events. Mengascini’s method was to create so-called memory snapshots, a snapshot of the objects stored in the memory.

    The snapshots were taken before and after executing a specific action, such as moving an avatar from A to B. Afterwards, an algorithm was used to check if any changes had occurred and if this information could be read from the web browser’s memory.

    Memories are easy to access

    “The most important finding is that these platforms lack the most basic security mechanisms,” Mengascini explains.

    “The main issue is that the browsers’ memory is too easy to access.” Even a non-expert could access both the source code and the actual objects in the memory with a little practice.

    “We also found that these platforms have messed up common good coding practices in web application development,” the CISPA researcher continues.

    “The developers of these platforms have missed the fact that due to a combination of unverified client-side information and excessive disclosure of information to the client, attacks are possible.”

    To illustrate what all this means in concrete terms, Mengascini gives an example: “Let’s assume there is a CISPA metaverse featuring an exact replica of our building. This would mean that every user’s computer would receive all the information about what is currently happening at CISPA: Who is talking to whom in which room, where individual people are physically located and how they are moving, including the exact positions of the walls.

    “Based on this, my computer calculates the virtual environment and ensures, for example, that I cannot listen to conversations in the director’s office because of a wall. However, the browser receives information about what is being said in the room. And that is bad.

    “Even if you are not able to listen in with a normal client, this information can be extracted quite easily by attackers. Therefore, it is important to not overshare information.”

    Potential attack scenarios

    According to Mengascini, this security gap gives rise to a number of possible attack scenarios. The key finding is that attackers can control the avatar and camera position of attackers and victims, as well as their appearance, independently of each other. For example, attackers can move their camera independently from their avatar, explains Mengascini.

    “This allows attackers to position themselves undetected in the room and to listen in,” Mengascini continues. Another possibility is that attackers can view another user’s camera content without them noticing.

    “It is like attackers putting on the user’s VR glasses without them realizing it,” explains the researcher. In order to prevent this, the server would have to retain as much information as possible, which would lead to increased computing power. Exactly this is, according to Mengascini, one of the reasons why the Metaverse platforms rely so heavily on web browsers.

    New research questions to take away

    In line with common practice in cyber security research, the three platforms were informed of the security gaps and given time to fix them. None of the three platforms has done this yet, which is why their names are still anonymized in the published paper.

    “From a researcher’s perspective, I am obviously concerned that the platforms don’t want to focus on security or don’t have the manpower to do so,” says Mengascini. “But at the same time, I think that we as researchers now have an open research question. Maybe it’s time for us to propose security mechanisms to prevent attacks or at least make it harder to carry them out.”

    And he already has ideas as to which protection mechanisms could be implemented. In particular, he plans to use the knowledge gained from the development of online games and transfer it to the Metaverse. However, Mengascini is aware that many approaches also have disadvantages and require extensive testing. A challenge that he wants to take up in the near future.

    More information:
    Andrea Mengascini et al, The Big Brother’s New Playground: Unmasking the Illusion of Privacy in Web Metaverses from a Malicious User’s Perspective, (2024). DOI: 10.60882/cispa.27102151.v3

    Provided by
    CISPA Helmholtz Center for Information Security

    Citation:
    Study reveals vulnerability of metaverse platforms to cyber attacks (2024, December 13)
    retrieved 13 December 2024
    from https://techxplore.com/news/2024-12-reveals-vulnerability-metaverse-platforms-cyber.html

    This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
    part may be reproduced without the written permission. The content is provided for information purposes only.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Vivo X300 Ultra Launch in India Confirmed: Check Full Specifications and Expected Price

    April 17, 2026

    OPPO F33 And F33 Pro Launched In India With 7,000mAh Battery, Dimensity 6360 Max: Check Price And Specs

    April 17, 2026

    Motorola Edge 70 Pro Launch Date in India and Full Specifications Confirmed Through Flipkart

    April 17, 2026

    Roblox’s AI assistant gets new agentic tools to plan, build, and test games

    April 17, 2026

    Moto Pad 60 Pro and Moto Pad 60 Neo Get a Price Hike in India: Check New Prices

    April 16, 2026

    OPPO Reno 16 Pro Full Specifications and Colourways Revealed: Check Launch Timeline for the Reno 16 Series

    April 16, 2026
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Vivo X300 Ultra Launch in India Confirmed: Check Full Specifications and Expected Price

    April 17, 2026

    OPPO F33 And F33 Pro Launched In India With 7,000mAh Battery, Dimensity 6360 Max: Check Price And Specs

    April 17, 2026

    Motorola Edge 70 Pro Launch Date in India and Full Specifications Confirmed Through Flipkart

    April 17, 2026

    Roblox’s AI assistant gets new agentic tools to plan, build, and test games

    April 17, 2026
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2026 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.