InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Apple Vision Pro vulnerability exposes virtual keyboard input to attackers
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Apple Vision Pro vulnerability exposes virtual keyboard input to attackers
Technology

Apple Vision Pro vulnerability exposes virtual keyboard input to attackers

September 13, 2024 3 Min Read
Share
Apple Vision Pro Vulnerability
SHARE
 
 

Details have emerged about a now-fixed security flaw affecting Apple’s Vision Pro mixed reality headsets that could allow a malicious attacker to infer data typed into the device’s virtual keyboard.

This attack: GAZE Prototypehas been assigned the CVE identifier CVE-2024-40865.

“This new attack allows for the inference of eye biometric information from avatar images and the reconstruction of text entered using gaze-controlled typing,” said a group of researchers from the University of Florida.

 

“The GAZEploit attack exploits a vulnerability inherent in gaze-controlled text input when users share their virtual avatars.”

Following responsible disclosure, Apple addressed the issue in visionOS 1.3, released on July 29, 2024. The company explained that the vulnerability affects a component called Presence.

“Input into the virtual keyboard may be inferred from Persona,” the company said in a security advisory, adding that it had addressed the issue by “suspending Persona when the virtual keyboard is active.”

Put simply, the researchers discovered that by analyzing the eye movements (or “gaze”) of a virtual avatar, they could determine what the headset-wearing user was typing on a virtual keyboard, essentially violating their privacy.

As a result, threat actors may be able to analyze virtual avatars shared over video calls, online conferencing apps, or live streaming platforms and perform remote keystroke guessing, which can then be exploited to extract sensitive information such as passwords.

The attack is carried out by a supervised learning model trained on persona recordings, eye aspect ratio (EAR) and gaze estimation to distinguish between typing sessions and other VR-related activities, such as watching movies or playing games.

See also  Containment, hot shots, evacuation orders: Understanding key wildfire terminology

In a next step, the gaze estimation direction on the virtual keyboard is mapped to specific keys and potential keystrokes are determined in a way that also takes into account the position of the keyboard in the virtual space.

“By remotely capturing and analyzing video of a virtual avatar, an attacker can reconstruct keystrokes,” the researchers said. “Notably, the GAZEploit attack is the first known attack in the field that leverages leaked gaze information to perform remote keystroke guessing.”

Share This Article
Twitter Copy Link
Previous Article Legendary sandbox game Besiege unveils roadmap packed with new features Legendary sandbox game Besiege unveils roadmap packed with new features
Next Article Harris supported the Green New Deal and now supports domestic oil drilling. Harris supported the Green New Deal and now supports domestic oil drilling.
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

US says Israel will accept latest Gaza ceasefire agreement, hold Hamas accountable
World News

US says Israel will accept latest Gaza ceasefire agreement, hold Hamas accountable

5 Min Read
Goodbye to Phishing
Technology

A must-have to combat credential theft

6 Min Read
How to earn more heat stamps in Frostpunk 2
Gaming

How to earn more heat stamps in Frostpunk 2

7 Min Read
Taylor Swift at the 2024 VMAs: Photos of the pop star's red carpet outfit
Celebrity

Taylor Swift at the 2024 VMAs: Photos of the pop star’s red carpet outfit

4 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?