❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Apple Fixes β€˜Bug’ in Vision Pro That Allowed Hackers To Fill Room with Bugs And Spiders

By: Alan J
24 June 2024 at 19:34

Apple Vision Pro

A recently discovered vulnerability (CVE-2024-27812) in the Apple Vision Pro headset allowed hackers to bypass device security mechanisms and flood user's environments with animated 3D objects – such as spiders and bugs – through a Safari exploit. These objects persisted even after exiting Safari, making for a uniquely unsettling environment. Apple addressed the vulnerability this month after security researcher Ryan Pickren had disclosed the flaw in February, awarding the researcher a bounty. The bug highlights the challenges in securing 'spatial computing' devices.

Spatial Hack in Apple Vision Pro Devices

Apple designed the Vision Pro with strict privacy controls. This includes limiting device apps to a default 'Shared Space' and mandating explicit user consent for more engaging and immersive content. Websites must also obtain explicit user permission to generate 3D content within a user's physical environment. [caption id="attachment_78754" align="alignnone" width="720"]Apple Vision Pro Source: ryanpickren.com[/caption] However, Pickren discovered that the AR Quick Look feature that had been introduced in 2018 for iOS remained active in the visionOS without the implementation of proper safeguards. This oversight allowed websites to manipulate HTML anchor tags to spawn unlimited 3D objects coupled with animations and spatial audio. By adding specific anchor tags to webpages, malicious websites can instruct Safari to render a 3D model, surprisingly without any form of user interaction. "If the victim just views our website in Vision Pro, we can instantly fill their room with hundreds of crawling spiders and screeching bats," Pickren explained. "Freaky stuff," he exclaimed. [caption id="attachment_78758" align="alignnone" width="1168"]Apple Vision Pro Spiders Source: ryanpickren.com[/caption] [caption id="attachment_78756" align="alignnone" width="1186"]Apple Vision Pro Bats Source: ryanpickren.com[/caption] The researcher stated that the exploit code is straightforward and that closing Safari doesn't get rid of the 3D objects, as they are handled by a separate application. "To make things even freakier – since these animated files are being handled by a separate application (Quick Look), closing Safari does not get rid of them," Pickren noted. He added, "There is no obvious way to get rid of them besides manually running around the room to physically tap each one."

Bug Reporting and Gaps in Vulnerability Assessment

After trying to disclose the flaw to Apple, the researcher felt the tech giant had downplayed its relation to spatial computing and the generation of 3D objects, instead focusing on the potential for system crashes and reboots. The CVE description claimed that the issue had been addressed by improving the file handling protocol, which the researcher believed was unrelated to the bug. This highlights the challenges of triaging and classifying bugs in emerging fields such as Spatial Computing. The researcher believes the bug's impact goes beyond simple system crashes or reboots, raising questions about the security and privacy of the technology and the need for reevaluating existing threat models. "Perhaps it's time for Apple to re-evaluate their Vision Pro threat model," Pickren suggested. "This is a deeply personal product and classic vulnerability triaging guidelines may not capture the full impact anymore." Media Disclaimer: This report is based on internal and external research obtained through various means. The information provided is for reference purposes only, and users bear full responsibility for their reliance on it. The Cyber Express assumes no liability for the accuracy or consequences of using this information.

Spatial Computing Hack Exploits Apple Vision Pro Flaw to Fill Room With Spiders, Bats

21 June 2024 at 08:52

A recently patched Vision Pro vulnerability was classified by Apple as a DoS issue, but a researcher has shown that it’s β€˜scary’.

The post Spatial Computing Hack Exploits Apple Vision Pro Flaw to Fill Room With Spiders, Bats appeared first on SecurityWeek.

Reports: Apple is halting its next high-end Vision in favor of something cheaper

18 June 2024 at 14:29
Vision Pro, seen from below, in a display with a bright white light strip overhead.

Enlarge (credit: Samuel Axon)

A report by tech news site The Information suggests that Apple is shifting its augmented reality priorities. The next high-end version of the Vision Pro has purportedly been canceled while work continues on a more affordable version with a reduced feature set.

Citing both an employee in Apple's headset supply chain and one working in headset manufacturing for Apple, the report claims that the cheaper Vision productβ€”perhaps around the $1,600 markβ€”is due before the end of 2025. Apple had originally intended to present this headset alongside the Vision Pro, similar to the models available in each iPhone release. The more affordable model would likely have fewer cameras, smaller speakers, and weigh less, though Apple has struggled to bring down the cost of the unit's displays.

Apple's efforts in augmented reality are closely watched by other players in the headset space, so even a momentary, situational step back from high-end headsets could have significant repercussions. The Information cites current and former Meta employees in describing how the company had killed plans for its own higher-end headset in January 2023, but it then began work on a new premium model five months after Apple's Vision Pro debut.

Read 3 remaining paragraphs | Comments

Apple’s new Vision Pro software offers an ultrawide virtual Mac monitor

10 June 2024 at 13:34
A floating Mac desktop over a table

Enlarge / A Mac virtual monitor in visionOS 2. (credit: Samuel Axon)

CUPERTINO, Calif.β€”Apple kicked off the keynote for its annual developer conference by announcing a new version of visionOS, the operating system that runs on the company's pricey but impressive Vision Pro mixed reality headset.

The updates in visionOS 2 are modest, not revolutionaryβ€”mostly iterative changes, quality-of-life improvements, and some features that were originally expected in the first version of visionOS. That's not too surprising given that visionOS just went out to users four months ago.

Vision Pro users hoping for multiple virtual Mac monitors will be disappointed that's not planned this time around, but Apple plans to add the next-best thing: Users will be able to take advantage of a larger and higher-resolution single virtual display, including a huge, wraparound ultrawide monitor mode that Apple says is equivalent to two 4K monitors.

Read 6 remaining paragraphs | Comments

What to expect at WWDC24: Big iOS changes, more Vision Pro, and so much AI

6 June 2024 at 14:07
A colorful logo that says

Enlarge / The logo for WWDC24. (credit: Apple)

Apple's annual developer conference, WWDC, kicks off in Cupertino, California, next week. As always, it will start with a livestream keynote on Monday morning at 10 am Pacific, 1 pm Eastern. We'll be in attendance reporting on the event, so let's take a moment to take stock of what we expect to see next week.

But first, let's note something we don't think we'll see: Due to some peculiarities about Apple's upgrade cycles, as well as a push toward the M4, we're not actually expecting any major hardware announcements at WWDC this year.

That's OK, though, because it looks like it's going to be a big one for software news. iOS has seen relatively modest updates in the past couple of years, but that's about to change.

Read 26 remaining paragraphs | Comments

❌
❌