Quest Bootloader Unlocker
Downgrades the inactive slot to a build with a vulnerable bootloader, boots it, and unlocks through CVE-2021-1931. Quest 1 and Quest 2.
A headset sitting in its bootloader shows “USB Update Mode” on the headset screen — that is what fastboot looks like on a Quest. Connect it with Connect bootloader, not Connect headset.
Windows: the headset needs a driver for its ADB interface and another for its bootloader — they are separate USB devices. Install Meta's ADB drivers before connecting. If the bootloader still does not appear in the picker later, bind that interface to WinUSB with Zadig.
Checking WebUSB support…
Procedure
Device
Nothing connected. Connect the headset over ADB and its fingerprint, build, slots and the checks run against them appear here.
Log
Restore a backup
Independent recovery path: connect the headset, and this roots it with ionstack and writes the images back. No downgrade, no fastboot, no unlock. It needs a working adb shell, so it can only repair the inactive slot from a device that still boots — if the active slot is dead there is no shell to run the exploit in. The untouched other slot is what protects you there, not this.
.zip saved by this tool, or loose
.img files — for backups from another browser profile
or machine