The rapid adoption of augmented reality (AR), virtual reality (VR), and extended reality (XR) technologies has introduced a distinct cybersecurity attack surface shaped by continuous biometric and spatial data collection, immersive interfaces, and multi-user collaborative environments. While individual studies have examined specific threats such as privacy leakage, side-channel attacks, and social engineering within immersive systems, a consolidated mapping of threats and their corresponding mitigation strategies across the AR/VR/XR domain remains limited. This study presents a systematic literature review guided by the PRISMA 2020 reporting framework to synthesize indexed research on cybersecurity threats and mitigations in AR/VR/XR published between 2018 and 2026. A structured search strategy combining terms related to immersive technologies and cybersecurity was applied across major computer-science literature sources, followed by criteria-based screening, yielding 45 studies included in the final synthesis. The review organizes threats into six categories: privacy and data leakage, side-channel and input-inference attacks, authentication and access-control weaknesses, perceptual manipulation and social engineering, malware and session hijacking, and physical safety risks. Correspondingly, five categories of mitigation strategies are identified: privacy-preserving techniques, detection and defense frameworks, authentication mechanisms, policy and risk-assessment frameworks, and interface- or awareness-based defenses. The synthesis reveals that mitigation research lags behind threat identification, particularly for perceptual manipulation and multi-user collaborative attacks. These findings offer a structured reference for researchers and developers seeking to design more secure immersive systems and highlight priority directions for future empirical research.
Copyrights © 2026