QuestStack bootloader frees original Meta Quest from Meta's servers
A new exploit called QuestStack grants full root access to the original Meta Quest headset, freeing it from reliance on Meta's servers and services. The privilege escalation attack gives developers and enthusiasts complete control over the 2019 hardware, which Meta stopped supporting in 2023. The bootloader integrates known Android fastboot vulnerabilities into a streamlined process completable via a web interface after connecting the headset to a PC. This allows sideloading apps without a Meta Developer account and bypassing initial setup login requirements, even if Meta shuts down supporting servers. Tinkerers are exploring new capabilities, such as enabling a 90 Hz refresh rate previously locked to 72 Hz. This follows a 2021 precedent when Meta's then-CTO John Carmack released a similar root access update for the Oculus Go, aiming to preserve hardware usability long after server shutdowns.