Quest Bootloader Unlocker

Downgrades the inactive slot to a build with a vulnerable bootloader, boots it, and unlocks through CVE-2021-1931. Quest 1 and Quest 2.

GitHub

A headset sitting in its bootloader shows “USB Update Mode” on the headset screen — that is what fastboot looks like on a Quest. Connect it with Connect bootloader, not Connect headset.

Checking WebUSB support…

Procedure

    Device

    Nothing connected. Connect the headset over ADB and its fingerprint, build, slots and the checks run against them appear here.

      Log

      
                

      Restore a backup

      Independent recovery path: connect the headset, and this roots it with ionstack and writes the images back. No downgrade, no fastboot, no unlock. It needs a working adb shell, so it can only repair the inactive slot from a device that still boots — if the active slot is dead there is no shell to run the exploit in. The untouched other slot is what protects you there, not this.

      a .zip saved by this tool, or loose .img files — for backups from another browser profile or machine

      Confirm

      Notice