Apple has fixed a visionOS vulnerability that allowed a hacker to fill a Vision Pro user's virtual space with 3D animated objects.
When spelled out like this, it doesn't sound that scary, but replaced "3D animated objects" with spiders, bats, snakes, or anything else that scares you, and you've got yourself one of the most intriguing and ominous bugs we've ever heard of.
SEE ALSO: Apple reportedly gives up on Vision Pro 2, focusing on cheaper model insteadThe vulnerability for was discovered by Ryan Pickren, an independent researcher who already found a couple of bugs in Apple's software, including nasty iPhone and Mac camera issues. Pickren told Mashable via email that he believes the bug he'd found in visionOS allows for the first "spatial computing" hack. He also said that Apple awarded him a bounty for finding and describing the issue.
The bug stems from the way visionOS handles apps that can spawn 3D objects in your virtual space while you're using the Vision Pro. As Pickren explained on his blog, the company severely restricted who and what can do this in most cases, but "forgot" about an older, web-based 3D model viewing standard called Apple AR Kit Quick Look. By adding some simple code to a website, a hacker could bypass Apple's restrictions and launch "an arbitrary number of 3D, animated, sound-creating, objects without any user interaction whatsoever."
Pickren supplied some examples by tapping into a lot of folks' worst nightmares: by adding virtual spiders and bats into a Vision Pro user's virtual space.
Fortunately, Apple fixed this vulnerability in visionOS 1.2, which launched earlier this month, though the company's description (unsurprisingly) don't mention eight-legged arthropods.
In any case, it appears Vision Pro users are safe from 3D monsters bursting into their virtual life — for now.
Copyright © 2023 Powered by
Apple fixes scary Vision Pro bug that allowed hackers to fill your virtual room with spiders-蜻蜓点水网
sitemap
文章
22
浏览
1
获赞
4
Best Bose headphones deal: Save $100 on the QuietComfort Ultra
SAVE $100:As of April 1, Bose QuietComfort Ultra noise-canceling headphones are available for $329 aThis phone company is turning heads by being more ambitious than Apple
When it comes to smartphones, everyone looks to Apple or Samsung or any of a handful of establishedForget data. Free labor is Facebook's lifeblood
Chances are, you work for Facebook. You probably don't have an office or an ID card. And you almostGwyneth Paltrow's Goop suggests you use coffee to clean your poop chute. Don't.
No matter what Gwyneth Paltrow's dubious health website tells you, please talk to your doctor before21 Halloween group costumes ideas to achieve your ultimate squad goals
Whether or not you appreciate spooky things, Halloween gives you the perfect excuse to dress up withSnapchat's Snap Maps is live on map.snapchat.com for Official Stories
Snapchats from all over the world can be easily viewed online. On Monday, Snapchat released map.snapThere's only one good name for the next iPhone
No more numbers, no more upgrade treadmills: When Apple launches its new lineup of iPhones, there's$200 million worth of cryptocurrency goes missing from BitGrail exchange
Another day, another high-profile cryptocurrency hack -- though in this case, the details are even mChrissy Teigen uses Twitter to get John Legend to pick up the phone
It's excruciating, waiting for someone to answer a message. Maybe it says "delivered" but not "seen"Otter app transcribes any verbal conversation into searchable text
Anyone who's ever transcribed an audio interview into text knows what a painfully slow process thatSlack makes big change to direct message privacy settings
Your boss can probably already read your Slack direct messages. And if they can't? Well, Slack may bApple targets Android users with new 'Switch to iPhone' ad campaign
There's a certain aesthetic that consumers have come to expect from Apple: black backgrounds, hip-hoPutting the iPhone X's Face ID to the contouring test
One of the coolest features of the iPhone X is the Face ID facial recognition. While it trips up onDue to fraud, LL Bean ends lifetime returns, blames social media
Congratulations, internet! We've ruined another glorious thing.On Friday, beloved cozy and outdoors-Fake 'Elon Musk' scams Twitter users out of cryptocurrency
People, please please pleaselisten closely: Elon Musk is not giving away Ether. Scammers have swarme