【Thriller Archives】
Apple's Vision Pro has a way of showing the world a virtual version of you while you interact with others in virtual reality. Unfortunately,Thriller Archives this very feature – called Persona – could've been used by hackers to steal a Vision Pro user's sensitive data.
The security flaw was discovered by a group of six computer scientists from the University of Florida's Department of Computer Science, and it was first reported on by Wired.
The GAZEploit attack, as it was dubbed by the researchers, works by tracking the eye movements of a user's Persona to identify when they're typing something on the Vision Pro's virtual keyboard. The researchers discovered that users tend to direct their gaze onto specific keys that they're about to click, and were able to construct an algorithm that identified what the users were typing. The results were quite accurate; for example, the researchers were able to identify the correct letters of users' passwords 77 percent of the time. When it came to detecting what people were typing in a message, the results were accurate 92 percent of the time.
You May Also Like
The researchers disclosed the vulnerability to Apple back in April, and Apple fixed it in visionOS 1.3, which came out in July. In the release notes, Apple says that the flaw enabled inputs to the virtual keyboard to be inferred from Persona.
"The issue was addressed by suspending Persona when the virtual keyboard is active," Apple wrote in the release notes. Vision Pro users who haven't yet updated to the latest version are advised to do so as soon as possible.
Related Stories
- Apple gets FDA green light on AirPods Pro hearing aid mode
- All of Apple's new iPhone 16 phones are capable of faster wired charging
- The best Apple deals following Apple's September event
- Apple 'Glowtime' event 2024: iPhone 16, Apple Watch Series 10, AirPods 4, and everything else announced
- Apple event underwhelming? Wait for the iPhone 17.
While simply disabling Persona while the user is typing was a pretty simple fix, the flaw does raise the question of just how much info a malicious hacker could infer just by observing a virtual version of you.
SEE ALSO: Apple Vision Pro: I watched a Billie Eilish concert in Bora Bora — and I didn't need to spend a pennyThe researchers said that the attack hasn't been used against someone using Personas in the real world. But what makes this attack particularly dangerous is that it only requires a video recording of someone's Persona while the person was typing, meaning an attacker could still use it on an older video. It seems that the only way to mitigate this issue is to erase any publicly available videos where your Persona is visible while typing; we've reached out to Apple for clarification on what can be done to protect your data.
Topics Apple Cybersecurity
Search
Categories
Latest Posts
What a great week to be a woman in media!!
2025-06-26 00:36Tip: Use iMessage Tapbacks for impromptu polls
2025-06-26 00:18Yes, you can now pleasure yourself for a good cause
2025-06-25 23:41Nanny State of Mind
2025-06-25 22:13Popular Posts
The Precocious Socialist
2025-06-26 00:02Zoom update hides Meeting IDs to protect users from hackers
2025-06-25 23:0012 best book
2025-06-25 22:37A very special Trump supporter, a happy anniversary for workers
2025-06-25 22:07Featured Posts
Putting People First in Pennsylvania
2025-06-25 23:27Zoom is different on your phone, so here’s when to use it
2025-06-25 23:24The Afterlife of <em>Newsies</em>
2025-06-25 22:35Popular Articles
The Professional Friends of YouTube
2025-06-26 00:24The mysterious recycling company led by 2 Tesla execs
2025-06-26 00:14Zoom is different on your phone, so here’s when to use it
2025-06-25 22:23The Last Temptation of Paul Schrader
2025-06-25 22:18Newsletter
Subscribe to our newsletter for the latest updates.
Comments (96422)
Life Information Network
What a dogshit week.
2025-06-26 00:50Art Information Network
J.K. Rowling annihilates Trump supporter in 1 brutal tweet
2025-06-26 00:44Happiness Information Network
Rihanna won the Met Gala again. Goodnight, everyone.
2025-06-26 00:13Impression Information Network
Of course, the internet made a lot of memes out of the 2017 Met Gala
2025-06-25 23:50Dream Information Network
Bridging the Healthcare Divide in West Virginia
2025-06-25 22:20