CVE-2019-3562: Oculus Browser

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and potentially execute code. This affects the Oculus Browser starting from version 5.2.7 until 5.7.11.

Affected products

  • Oculus Oculus Browser: from 5.2.7, up to and including 5.7.11

Published 2019-04-29. Last modified 2026-06-17.