Developer Update - 5 February 2026

As the person who made that private exploit report and the public Canny, the only communication I got over a year and a half was “We do not guarantee a response other than the automated “ticket received” notification.” and the Canny being marked as tracked, which simply means it was put on the internal bug tracker, not that any action was being taken.

I’ve recently escalated another exploit in which remote users can launch a browser session without your action or consent and can DoS your device through memory exhaustion by doing so. It’s not even marked as tracked.

VRChat really needs to re-consider how they publicly approach security and transparency of it with their users. I am appreciative of the fact that this the group public exploit was finally fixed, but the lack of communication and the extremely long time that this exploit was left open leaves much to be desired.

1 Like