❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 28 June 2024Main stream

Apple’s Vision Pro goes on sale outside the US for the first time

28 June 2024 at 17:42
A mixed reality headset over a table in an Apple Store

Enlarge / A Vision Pro on display at an Apple Store in Tokyo. (credit: Apple)

Apple's Vision Pro headset went on sale outside the United States for the first time today, in the first of two waves of expanded availability.

The $3,499 "spatial computing" device launched back in February in the US, but it hasn't taken the tech world by storm. Part of that has been its regional launch, with some of the biggest markets still lacking access.

Apple announced that the product would be sold internationally during its keynote at the Worldwide Developers Conference earlier this month.

Read 6 remaining paragraphs | Comments

Before yesterdayMain stream

Apple Fixes β€˜Bug’ in Vision Pro That Allowed Hackers To Fill Room with Bugs And Spiders

By: Alan J
24 June 2024 at 19:34

Apple Vision Pro

A recently discovered vulnerability (CVE-2024-27812) in the Apple Vision Pro headset allowed hackers to bypass device security mechanisms and flood user's environments with animated 3D objects – such as spiders and bugs – through a Safari exploit. These objects persisted even after exiting Safari, making for a uniquely unsettling environment. Apple addressed the vulnerability this month after security researcher Ryan Pickren had disclosed the flaw in February, awarding the researcher a bounty. The bug highlights the challenges in securing 'spatial computing' devices.

Spatial Hack in Apple Vision Pro Devices

Apple designed the Vision Pro with strict privacy controls. This includes limiting device apps to a default 'Shared Space' and mandating explicit user consent for more engaging and immersive content. Websites must also obtain explicit user permission to generate 3D content within a user's physical environment. [caption id="attachment_78754" align="alignnone" width="720"]Apple Vision Pro Source: ryanpickren.com[/caption] However, Pickren discovered that the AR Quick Look feature that had been introduced in 2018 for iOS remained active in the visionOS without the implementation of proper safeguards. This oversight allowed websites to manipulate HTML anchor tags to spawn unlimited 3D objects coupled with animations and spatial audio. By adding specific anchor tags to webpages, malicious websites can instruct Safari to render a 3D model, surprisingly without any form of user interaction. "If the victim just views our website in Vision Pro, we can instantly fill their room with hundreds of crawling spiders and screeching bats," Pickren explained. "Freaky stuff," he exclaimed. [caption id="attachment_78758" align="alignnone" width="1168"]Apple Vision Pro Spiders Source: ryanpickren.com[/caption] [caption id="attachment_78756" align="alignnone" width="1186"]Apple Vision Pro Bats Source: ryanpickren.com[/caption] The researcher stated that the exploit code is straightforward and that closing Safari doesn't get rid of the 3D objects, as they are handled by a separate application. "To make things even freakier – since these animated files are being handled by a separate application (Quick Look), closing Safari does not get rid of them," Pickren noted. He added, "There is no obvious way to get rid of them besides manually running around the room to physically tap each one."

Bug Reporting and Gaps in Vulnerability Assessment

After trying to disclose the flaw to Apple, the researcher felt the tech giant had downplayed its relation to spatial computing and the generation of 3D objects, instead focusing on the potential for system crashes and reboots. The CVE description claimed that the issue had been addressed by improving the file handling protocol, which the researcher believed was unrelated to the bug. This highlights the challenges of triaging and classifying bugs in emerging fields such as Spatial Computing. The researcher believes the bug's impact goes beyond simple system crashes or reboots, raising questions about the security and privacy of the technology and the need for reevaluating existing threat models. "Perhaps it's time for Apple to re-evaluate their Vision Pro threat model," Pickren suggested. "This is a deeply personal product and classic vulnerability triaging guidelines may not capture the full impact anymore." Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.
❌
❌