Meta Horizon Security & Privacy Scorecard
Android
Activity is tracked across Meta, Google, Spotify, and Firebase services. Purchase and usage data flows through multiple analytics systems tied to the user's account. Some network connections send data with less protection than expected, but stored data and personal information are handled carefully.
Best for
VR enthusiasts comfortable with Meta's ecosystem
Findings
- 2 critical
- 1 high
- 8 medium
- 0 low
- 0 info
11 issues identified across security and privacy analysis.
Top security issues
- Global Cleartext HTTP Traffic Permitted
- Device PKE Private Keys Stored with Base64 Encoding Only
- TrustManager That Accepts All Certificates
Top privacy issues
- Cleartext HTTP Permitted for Meta Analytics Subdomains
- Pre-Consent Lifecycle Analytics Tracking
- Advertising ID Permission Without Advertising SDKs
Full analysis
Meta Horizon
What This Means for You
Activity is tracked across Meta, Google, Spotify, and Firebase services. Purchase and usage data flows through multiple analytics systems tied to the user's account. Some network connections send data with less protection than expected, but stored data and personal information are handled carefully.
Recommendation: Use With Caution
Best For: VR enthusiasts comfortable with Meta's ecosystem
Key Findings
Data Security - 2 findings (2 medium)
Network Security - 4 findings (2 critical, 1 high, 1 medium)
Code Safety - 0 findings
Privacy - 2 findings (2 medium)
Privacy Concerns
What Data is Collected
Meta Horizon collects account information, VR interaction patterns, purchase history, and usage activity linked to the user's Meta account. This includes how users navigate experiences, in-app purchases processed through Google Play Billing, and audio preferences tied to the Spotify SDK.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Meta platform (Facebook Core SDK, Facebook Analytics, Facebook RTC, Facebook MQTT): activity, usage, and real-time communication data shared within Meta's ecosystem
- Google services (Firebase Cloud Messaging, Firebase Core, Google Analytics, Google Play Services, Google Sign-In, Google Cast, Google Play Billing): account identifiers and usage metrics
- Spotify SDK: audio and music preference data associated with the user's session
- Networking libraries (OkHttp, Retrofit, React Native): used for app functionality and server communication
Understanding the Scores
| Category | Score |
|---|---|
| Security | 73/100 |
| Privacy | 97/100 |
| Data Security | 92/100 |
| Network Security | 69/100 |
| Code Safety | 96/100 |
| Data Collection | 97/100 |
| Data Sharing | 100/100 |
| User Control | 97/100 |
Positive Security Features
- Data stored on device is well-protected against unauthorized access
- The app's code integrity measures are strong, reducing the risk of unwanted modification
- Data sharing practices are transparent and meet high privacy standards
- User controls provide meaningful options for managing personal data
- No unnecessary data collection practices were identified
Areas for Improvement
- Some network connections do not enforce the strongest available protections, which means user data may not be fully protected during transmission under certain conditions.
- A small number of network-level configurations allow connection patterns to be observed by third parties, even when content itself is protected.
- Aligning network security practices with the app's otherwise strong data handling standards would provide more consistent protection across all data flows.
About This Analysis
App Details
- App: Meta Horizon
- Package: com.oculus.twilight
- Version: 363.0.0.30.297
- Scan Date: 2026-03-26
- Total Findings: 11 (2 critical, 1 high, 8 medium)
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #4 (current) | 80/100 | |
| #3 | 80/100 | |
| #1 | 79/100 |