Apple's Vision Pro has a way of showing the world a virtual version of you while you interact with others in virtual reality. Unfortunately,Farmer’s Wife: Handle with Care! Part 1: Angel Advent this very feature – called Persona – could've been used by hackers to steal a Vision Pro user's sensitive data.
The security flaw was discovered by a group of six computer scientists from the University of Florida's Department of Computer Science, and it was first reported on by Wired.
The GAZEploit attack, as it was dubbed by the researchers, works by tracking the eye movements of a user's Persona to identify when they're typing something on the Vision Pro's virtual keyboard. The researchers discovered that users tend to direct their gaze onto specific keys that they're about to click, and were able to construct an algorithm that identified what the users were typing. The results were quite accurate; for example, the researchers were able to identify the correct letters of users' passwords 77 percent of the time. When it came to detecting what people were typing in a message, the results were accurate 92 percent of the time.
The researchers disclosed the vulnerability to Apple back in April, and Apple fixed it in visionOS 1.3, which came out in July. In the release notes, Apple says that the flaw enabled inputs to the virtual keyboard to be inferred from Persona.
"The issue was addressed by suspending Persona when the virtual keyboard is active," Apple wrote in the release notes. Vision Pro users who haven't yet updated to the latest version are advised to do so as soon as possible.
While simply disabling Persona while the user is typing was a pretty simple fix, the flaw does raise the question of just how much info a malicious hacker could infer just by observing a virtual version of you.
SEE ALSO: Apple Vision Pro: I watched a Billie Eilish concert in Bora Bora — and I didn't need to spend a pennyThe researchers said that the attack hasn't been used against someone using Personas in the real world. But what makes this attack particularly dangerous is that it only requires a video recording of someone's Persona while the person was typing, meaning an attacker could still use it on an older video. It seems that the only way to mitigate this issue is to erase any publicly available videos where your Persona is visible while typing; we've reached out to Apple for clarification on what can be done to protect your data.
Topics Apple Cybersecurity
Wow, budget airline WOW Air is just doneTinder puts a stop to fake height on profilesApple's AirPower fail is an unprecedented embarrassmentThe Weather Channel invites you to a have a politicsA casting announcement led to upset over TV's lack of diverse romanceWell, that incredible optical illusion at the Louvre has been destroyed by the publicYouTube restricts videos from farAlton Sterling's son spent his 16th birthday with Kanye West and Kim KardashianLil Wayne says he doesn't feel 'connected' to Black Lives MatterHey Obama, here's how to troll Trump like a proA Sega Genesis Mini will hit stores this fallBehold the hideous 6The 8 best funny horror movies for the easily spookedDbrand to sell AirPower skins because heck, why notRoku's new remote lets your dog control the TVTwitter users want to trick Clinton supporters to 'vote' via textWoman sexually assaulted by Brock Turner shares emotional essay about being a survivorJeff Bezos' affair leak may have been Saudi retaliationThe bunnies in Jordan Peele's 'Us' are ruining Easter for peopleLeaked image shows 'iPhone 11' with what appears to be three cameras 'Banana for scale' is put to bed by this very weird apartment listing 'D*ckhead' escape dog somehow knows how to catch trains all over town Kellyanne Conway's tweet about Hillary's emails is coming back to haunt her Adorable story of star Lyft is being mighty elusive about whether it'll finally come to Australia Here's how Melissa McCarthy ended up playing Sean Spicer on 'Saturday Night Live' Some of Google's Nest cameras are vulnerable to attacks Doctor performs hilariously graphic rap about safe sex for senior citizens Japan moves closer to acceptance, with another city recognising same Once and for all, people: Stop bringing snakes on planes, because stuff like this happens Durex is launching jeans and people are majorly amused Drake just shattered his Spotify record with an Apple Music record Trump says people don't know Abraham Lincoln was in the party of Lincoln That time 'Rogue One' almost brought its villain back from the dead Women's mansplaining experiences will make you want to throw things Netflix's 'Death Note' teaser trailer opens the book on horror and destruction Walking with Neil Gaiman is the best thing you can do in the winter Pray for the Cadbury social media manager who's frantically fending off trolls Jared Kushner is building a skyscraper and, well, it looks like a dick This student's hilariously bizarre campaign video escalates so damn fast
3.5526s , 10138.3359375 kb
Copyright © 2025 Powered by 【Farmer’s Wife: Handle with Care! Part 1: Angel Advent】,Pursuit Information Network