// ARS TECHNICA — CYBERSECURITY
New bootloader lets you take the "Meta" out of the original Meta Quest
Privilege escalation attack grants “full control” and freedom from Meta’s servers/apps.
Remember the original Quest headset that Meta (then Oculus) trumpeted back in 2019? Meta seems to hope you don’t, since the company officially stopped supporting the wireless VR headset in 2023 to focus on the more popular Quests 2 and 3. Luckily, tinkerers haven’t similarly abandoned the hardware and recently released a new root-access exploit and bootloader that gives “developers and enthusiasts full control over Quest 1 hardware.”
The QuestStack project integrates previously known vulnerabilities in the Quest’s Android fastboot process into a privilege escalation chain that leads easily to full root access on the device. The bootloading process is now streamlined enough that it can be completed without any downloads through a web interface after connecting the headset to a PC.
With this exploit, the original Quest hardware can now be officially divorced from any reliance on Meta’s servers or services to be useful. That means enterprising Quest owners should be able to sideload apps without needing to register for a Meta Developer account and activating Developer Mode through Meta’s mobile app. It also means users should be able to go through the initial setup and login steps for a fresh Quest headset even if and when Meta decides to shut down the servers that currently support this process.
Tinkerers are also in the early stages of figuring out how root access can unlock previously unavailable features on the Quest hardware. That includes activating the 90Hz refresh rate that John Carmack admitted in 2019 was being held back to 72Hz in the OS for performance reasons. There are also projects in the works to get other VR controllers working with the original Quest.
In 2021, Meta’s then-CTO John Carmack released an official “full root access” update for the Oculus Go, the Quest’s wireless predecessor. At the time, Carmack said he hoped that update would allow tinkerers to “repurpose the [Go] hardware for more things today” and ensure that “a randomly discovered shrink wrapped [Go] headset twenty years from now [would] be able to update to the final software version, long after over-the-air update servers have been shut down.”
QuestStack author starseed12345 speculates on Github that a similar exploit could probably enable root access on Quest 2 headsets running older firmware versions but that currently “the chance of bricking outweighs the benefit of unlocking the bootloader.”