Key facts
- A new bootloader allows users to gain full control over original Meta Quest headsets.
- This exploit enables users to bypass Meta's servers and apps.
Tinkerers have developed a new bootloader that allows users to gain full control over original Meta Quest headsets, bypassing Meta's servers and unlocking previously unavailable features. This exploit could enable higher refresh rates and compatibility with other VR controllers.

This development empowers users to customize and extend the functionality of their Meta Quest headsets beyond the manufacturer's intended limitations, potentially revitalizing older hardware and fostering a more open VR ecosystem.
Tinkerers have developed a new bootloader that allows users to gain full control over original Meta Quest headsets, effectively freeing them from Meta's servers and applications. This privilege escalation attack grants "full control" over the hardware.
This development opens the door to unlocking previously unavailable features. Users may be able to activate the 90Hz refresh rate, which Meta's former CTO John Carmack admitted in 2019 was intentionally limited to 72Hz in the operating system for performance reasons. Additionally, projects are in progress to enable compatibility with other VR controllers for the Quest hardware.
In 2021, Carmack released an official "full root access" update for the Oculus Go, the Quest's predecessor. He expressed hope that this update would allow tinkerers to repurpose the hardware and ensure its long-term usability even after official server support ends.
QuestStack author starseed12345 has speculated on GitHub that a similar exploit could potentially enable root access on Quest 2 headsets running older firmware versions. However, they caution that currently, the risk of bricking the device outweighs the benefits of unlocking the bootloader.