Apple's Vision Pro has a way of showing the world a virtual version of you while you interact with others in virtual reality. Unfortunately,Widow who Fell For Her Son’s Friend’s Stuff She Met On A Matching App (2025) this very feature – called Persona – could've been used by hackers to steal a Vision Pro user's sensitive data.
The security flaw was discovered by a group of six computer scientists from the University of Florida's Department of Computer Science, and it was first reported on by Wired.
The GAZEploit attack, as it was dubbed by the researchers, works by tracking the eye movements of a user's Persona to identify when they're typing something on the Vision Pro's virtual keyboard. The researchers discovered that users tend to direct their gaze onto specific keys that they're about to click, and were able to construct an algorithm that identified what the users were typing. The results were quite accurate; for example, the researchers were able to identify the correct letters of users' passwords 77 percent of the time. When it came to detecting what people were typing in a message, the results were accurate 92 percent of the time.
The researchers disclosed the vulnerability to Apple back in April, and Apple fixed it in visionOS 1.3, which came out in July. In the release notes, Apple says that the flaw enabled inputs to the virtual keyboard to be inferred from Persona.
"The issue was addressed by suspending Persona when the virtual keyboard is active," Apple wrote in the release notes. Vision Pro users who haven't yet updated to the latest version are advised to do so as soon as possible.
While simply disabling Persona while the user is typing was a pretty simple fix, the flaw does raise the question of just how much info a malicious hacker could infer just by observing a virtual version of you.
SEE ALSO: Apple Vision Pro: I watched a Billie Eilish concert in Bora Bora — and I didn't need to spend a pennyThe researchers said that the attack hasn't been used against someone using Personas in the real world. But what makes this attack particularly dangerous is that it only requires a video recording of someone's Persona while the person was typing, meaning an attacker could still use it on an older video. It seems that the only way to mitigate this issue is to erase any publicly available videos where your Persona is visible while typing; we've reached out to Apple for clarification on what can be done to protect your data.
Topics Apple Cybersecurity
Ridiculously adorable skateboarding pup crashes into the BBCWe are what we wear — and that matters a lot in job interviewsElon Musk's Boring Company starts it's tunneling projectThe Prince of Norway is the internet's new favourite royal family memberUK startup Improbable just raised half a billion dollars to build the MatrixEven the experts think some passwordSnap CEO Evan Spiegel is here to lose money and earn your trustPrepare to have your face scanned at airports across AmericaSaturn's moon Titan looks like a pretty chill place in new photosUnited flight evacuated because of a scorpionGoogle's chat app Allo takes Bitmoji to the next level'Game of Thrones' stunt set 20 people on fire in a dayJennifer Aniston says modernGoogle's chat app Allo takes Bitmoji to the next levelGerman insurance ad slammed for its 'cheap ripoff' of a Maori hakaMysterious bots flood the FCC with fake antiApple just gave away all the iPhone camera’s secretsPlease stop driving into this house, it's had 48 cars crash into it in 2016 aloneSaturn's moon Titan looks like a pretty chill place in new photosMicrosoft unveils the next version of Windows 'Fortnite' teams up with 'Obi Trump attacks Kavanaugh’s accuser in a string of despicable tweets An old Lady Gaga tweet got turned into an honestly great meme This political ad has the best surprise ending of, uh, all time YouTube rolls out new content Michelle Obama is just as tired of politics as you are 10 most watched TV shows this week: True crime and sci GoFundMe has launched a verified fundraising hub for the Robb Elementary School shooting Jack Dorsey exits Twitter's board of directors New Zealand Prime Minister Jacinda Ardern brings baby to UN General Assembly, makes history A woman accosted a security guard with a fanny pack containing a pigeon Why 'This Is Us' penultimate episode "The Train" made Mandy Moore throw up TikTok is going LIVE, with Twitch Brave lil' raccoon climbs up tall building, jumps off, survives Twitter pays $150 million fine over privacy and Elon Musk has thoughts Apple's new accessibility features: door detection and live captions Laura Dern and Sam Neill on 'inappropriate' age gap in Jurassic Park Time's Up calls for walkout following Brett Kavanaugh accusations Google is filing for bankruptcy in Russia Apple confirms WWDC 2022 begins June 6
2.8659s , 10139.46875 kb
Copyright © 2025 Powered by 【Widow who Fell For Her Son’s Friend’s Stuff She Met On A Matching App (2025)】,Warmth Information Network