Apple's Vision Pro has a way of showing the world a virtual version of you while you interact with others in virtual reality. Unfortunately,Christmas Night (2024) Hindi Short Film this very feature – called Persona – could've been used by hackers to steal a Vision Pro user's sensitive data.
The security flaw was discovered by a group of six computer scientists from the University of Florida's Department of Computer Science, and it was first reported on by Wired.
The GAZEploit attack, as it was dubbed by the researchers, works by tracking the eye movements of a user's Persona to identify when they're typing something on the Vision Pro's virtual keyboard. The researchers discovered that users tend to direct their gaze onto specific keys that they're about to click, and were able to construct an algorithm that identified what the users were typing. The results were quite accurate; for example, the researchers were able to identify the correct letters of users' passwords 77 percent of the time. When it came to detecting what people were typing in a message, the results were accurate 92 percent of the time.
The researchers disclosed the vulnerability to Apple back in April, and Apple fixed it in visionOS 1.3, which came out in July. In the release notes, Apple says that the flaw enabled inputs to the virtual keyboard to be inferred from Persona.
"The issue was addressed by suspending Persona when the virtual keyboard is active," Apple wrote in the release notes. Vision Pro users who haven't yet updated to the latest version are advised to do so as soon as possible.
While simply disabling Persona while the user is typing was a pretty simple fix, the flaw does raise the question of just how much info a malicious hacker could infer just by observing a virtual version of you.
SEE ALSO: Apple Vision Pro: I watched a Billie Eilish concert in Bora Bora — and I didn't need to spend a pennyThe researchers said that the attack hasn't been used against someone using Personas in the real world. But what makes this attack particularly dangerous is that it only requires a video recording of someone's Persona while the person was typing, meaning an attacker could still use it on an older video. It seems that the only way to mitigate this issue is to erase any publicly available videos where your Persona is visible while typing; we've reached out to Apple for clarification on what can be done to protect your data.
Topics Apple Cybersecurity
USC vs. Minnesota football livestreams without cable: kickoff time, streaming deals, and moreMeta can’t use LGBTQ identity to target ads, EU court rulesThe best early October Prime Day drone dealsBest iPad deal: Save over $100 on the Apple iPad 9th GenNYT Strands hints, answers for October 7Early Prime Day 2024 PlayStation 5 dealsBest early October Prime Day MacBook deals: Shop recordRavens vs. Bengals 2024 livestream: How to watch NFL for freeBest video game deal: Get 'Madden NFL 25' for $22 off at AmazonAlabama vs. Vandy football livestreams without cable: Kickoff time, streaming deals, and moreUT Vols vs. Arkansas football livestreams: kickoff time, streaming deals, and moreEarly Oct. Prime Day gaming deals: PC discounts aplentyPrime Day deal: Get the Apple M2 MacBook Air at its lowest price everBest free ChatGPT coursesNYT mini crossword answers for October 6Adult creators launch campaign against Project 2025Best headphones deal: $220 off Sony WHEarly Prime Day deals on noiseNYT mini crossword answers for October 6Wordle today: The answer and hints for October 5 Axe believes its new ad will make you rethink macho stereotypes The incredible ways people with disabilities customize their tech to thrive Tencent is creating an entire town dedicated to esports The internet had a perfect rebuttal to Gregg Popovich calling out a 'dirty' play Kendall Jenner face NFL star says his team is the 'perfect place' for Colin Kaepernick Gay jokes about Trump aren't funny — they're dangerous The first TV with built Bill Cosby comments on sexual assault allegations in first public interview in 2 years Driving test that uses only your hearing is totally freaking people out Ransomware hackers are so desperate to explain Bitcoin they've set up IT departments Discord's Slack Sailor Moon outfits are now available in even more sizes Apple Park Campus consumed the last 2 years of Steve Jobs' life Toyota backs adorably tiny flying car that could light the Olympic flame Samsung says it sold 5 million units of its Galaxy S8 in 25 days 'The Daily Show's massive tweet thread makes the GOP's hypocrisy perfectly clear Why Gregg Popovich is such a powerful critic of Donald Trump Supermarket worker slams the woman who shamed her for wearing makeup at work Americans have no idea where North Korea is but are pretty sure it's in Australia
2.6772s , 8225.8828125 kb
Copyright © 2025 Powered by 【Christmas Night (2024) Hindi Short Film】,Charm Information Network