Meta Horizon Security & Privacy Scorecard

Android

80
Overall trust score
Acceptable
73
Security
97
Privacy

Activity is tracked across Meta, Google, Spotify, and Firebase services. Purchase and usage data flows through multiple analytics systems tied to the user's account. Some network connections send data with less protection than expected, but stored data and personal information are handled carefully.

Best for

VR enthusiasts comfortable with Meta's ecosystem

Findings

  • 2 critical
  • 1 high
  • 8 medium
  • 0 low
  • 0 info

11 issues identified across security and privacy analysis.

Top security issues

  • Global Cleartext HTTP Traffic Permitted
  • Device PKE Private Keys Stored with Base64 Encoding Only
  • TrustManager That Accepts All Certificates

Top privacy issues

  • Cleartext HTTP Permitted for Meta Analytics Subdomains
  • Pre-Consent Lifecycle Analytics Tracking
  • Advertising ID Permission Without Advertising SDKs

Full analysis

Meta Horizon

What This Means for You

Activity is tracked across Meta, Google, Spotify, and Firebase services. Purchase and usage data flows through multiple analytics systems tied to the user's account. Some network connections send data with less protection than expected, but stored data and personal information are handled carefully.

Recommendation: Use With Caution

Best For: VR enthusiasts comfortable with Meta's ecosystem

Key Findings

Data Security - 2 findings (2 medium)

Network Security - 4 findings (2 critical, 1 high, 1 medium)

Code Safety - 0 findings

Privacy - 2 findings (2 medium)

Privacy Concerns

What Data is Collected

Meta Horizon collects account information, VR interaction patterns, purchase history, and usage activity linked to the user's Meta account. This includes how users navigate experiences, in-app purchases processed through Google Play Billing, and audio preferences tied to the Spotify SDK.

Third-Party Data Sharing

Data is shared with the following third-party services:

  • Meta platform (Facebook Core SDK, Facebook Analytics, Facebook RTC, Facebook MQTT): activity, usage, and real-time communication data shared within Meta's ecosystem
  • Google services (Firebase Cloud Messaging, Firebase Core, Google Analytics, Google Play Services, Google Sign-In, Google Cast, Google Play Billing): account identifiers and usage metrics
  • Spotify SDK: audio and music preference data associated with the user's session
  • Networking libraries (OkHttp, Retrofit, React Native): used for app functionality and server communication

Understanding the Scores

Category Score
Security 73/100
Privacy 97/100
Data Security 92/100
Network Security 69/100
Code Safety 96/100
Data Collection 97/100
Data Sharing 100/100
User Control 97/100

Positive Security Features

  • Data stored on device is well-protected against unauthorized access
  • The app's code integrity measures are strong, reducing the risk of unwanted modification
  • Data sharing practices are transparent and meet high privacy standards
  • User controls provide meaningful options for managing personal data
  • No unnecessary data collection practices were identified

Areas for Improvement

  • Some network connections do not enforce the strongest available protections, which means user data may not be fully protected during transmission under certain conditions.
  • A small number of network-level configurations allow connection patterns to be observed by third parties, even when content itself is protected.
  • Aligning network security practices with the app's otherwise strong data handling standards would provide more consistent protection across all data flows.

About This Analysis

App Details

  • App: Meta Horizon
  • Package: com.oculus.twilight
  • Version: 363.0.0.30.297
  • Scan Date: 2026-03-26
  • Total Findings: 11 (2 critical, 1 high, 8 medium)

Versions & scan history

ScanDateOverall score
#4 (current) 80/100
#3 80/100
#1 79/100