The Vision Pro uses 3D avatars on calls and for streaming. These researchers used eye tracking to work out the passwords and PINs people typed with their avatars.

Archived version: https://web.archive.org/web/20240912100207/https://www.wired.com/story/apple-vision-pro-persona-eye-tracking-spy-typing/

you are viewing a single comment's thread
view the rest of the comments
[–] 22 points 2 years ago (5 children)

That should be an easy fix in a future software update by simply not replicating eye movement as soon as the user is looking at the keyboard.

  • source
  • hideshow 5 child comments
  • [–] 5 points 2 years ago (1 child)

    Sounds like what they already did: as soon as the virtual keyboard pops up the eye movement isn't transmitted as part of the avatar.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 5 points 2 years ago

    Oh I see. According to the article:

    The GAZEpolit researchers reported their findings to Apple in April and subsequently sent the company their proof-of-concept code so the attack could be replicated. Apple fixed the flaw in a Vision Pro software update at the end of July, which stops the sharing of a Persona if someone is using the virtual keyboard.

    An Apple spokesperson confirmed the company fixed the vulnerability, saying it was addressed in VisionOS 1.3.

  • source
  • parent