PT-2024-6869 · Visionos · Visionos
Hanqiu Wang
+5
·
Published
2024-07-29
·
Updated
2024-09-26
·
CVE-2024-40865
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
visionOS versions prior to 1.3
Description
The issue is related to the virtual keyboard in visionOS, where inputs may be inferred from Persona when the virtual keyboard is active. This could allow an attacker to determine what users are typing on the virtual keyboard by analyzing eye movements, compromising user privacy. The issue has been exploited in real-world attacks.
Recommendations
For visionOS versions prior to 1.3, the issue was addressed by suspending Persona when the virtual keyboard is active. To resolve the issue, update to visionOS 1.3. As a temporary workaround, consider disabling the virtual keyboard or restricting its use until the update is applied.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visionos