Urgent.News

What's breaking now, across thousands of outlets.

Tech

New bootloader lets you take the "Meta" out of the original Meta Quest

Privilege escalation attack grants "full control" and freedom from Meta's servers/apps.

New bootloader lets you take the "Meta" out of the original Meta Quest

The original Quest headset, launched by Meta (previously Oculus) in 2019, has been discontinued by the company since 2023 to concentrate on newer models. However, determined enthusiasts have not given up on the hardware. A new exploit and bootloader called QuestStack has been recently unveiled, granting developers and fans complete access to the Quest 1 device. This vulnerability in Quest's Android fastboot process has been woven into a privilege escalation chain leading to root access.

The updated bootloading procedure can now be accomplished through a web interface by merely linking the headset to a PC, eliminating the need for any downloads. With this exploit, the original Quest hardware can be entirely independent of Meta's servers or services, enabling users to sideload applications without registering for a Meta Developer account or activating Developer Mode via Meta's mobile application.

Furthermore, users should be able to perform the initial setup and login steps for a new Quest headset, even if Meta decides to shut down the servers that currently facilitate this process.

Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at arstechnica.com →

More in Tech

REST vs GraphQL in Practice

The Real Trade-offs After building APIs with both REST and GraphQL, I've learned that the choice isn't about which is "better" but about what your consumers need.

More from Tuesday 25 August →