Apple has fixed a zero-day vulnerability in Vision Pro that “may” have already been exploited by hackers

Apple has fixed a zero-day vulnerability in Vision Pro that

A day after publishing the first press reviews of the headset, Apple released the first security patch for the Vision Pro – to address a zero-day vulnerabilityApple has patched a zero-day vulnerability in Vision Pro that Apple has fixed a zero-day vulnerability in Vision Pro that A software vulnerability that is not yet known to users or software developers, and against which protection mechanisms have not yet been developed, and which may have already been exploited by hackers.

The visionOS 1.0.2 update (the OS that runs on Vision Pro) addresses a vulnerability in WebKit, the engine that runs Safari and other web applications. Apple says the bug, if exploited, could allow malicious code to run on an affected device.

The same vulnerability, officially designated as CVE-2024-23222, was patched by Apple last week via the iOS 17.3 update for iPhone, iPad, Mac and Apple TV – all of which rely on WebKit.

Attackers often target weaknesses in WebKit, using them as a way to penetrate the underlying operating system of a device and gain access to a user’s personal data. Engine bugs can sometimes be exploited when a victim visits a malicious domain in their web browser or another application’s browser.

The Vision Pro is expected to be available in US stores as early as Friday, February 2nd for $3,500 and a $149 surcharge for prescription lenses.

Apple has advertised that its mixed reality headset will initially support more than a million apps, including apps from Disney, TikTok, Amazon, Paramount and others. However, according to Bloomberg’s Mark Gurman, about 99% of those are not new software for visionOS, but existing iPad versions. Thus, all of them will automatically appear in the Vision Pro App Store – unless the developers refuse, as, for example, Netflix, Spotify and YouTube plan to do.

Microsoft 365 apps will be available on Apple Vision Pro starting February 2

Source: Techcrunch

Related Posts

UK to regulate cryptocurrency memes: illegal advertising

Britain’s financial services regulator has issued guidance to financial services companies and social media influencers who create memes about cryptocurrencies and other investments to regulate them amid…

unofficial renders of the Google Pixel 9 and information about the Pixel 9 Pro XL

The whistleblower @OnLeaks and the site 91mobiles presented the renders of the Google Pixel 9 phone. Four images and a 360° video show a black smartphone with…

Embracer to sell Gearbox (Borderlands) to Take-Two (Rockstar and 2K) for $460 million

Embracer continues to sell off assets – the Swedish gaming holding has just confirmed the sale of The Gearbox Entertainment studio to Take-Two Interactive. The sum is…

photo of the new Xbox X console

The eXputer site managed to get a photo of a new modification of the Microsoft Xbox game console. The source reports that it is a white Xbox…

Israel Deploys Massive Facial Recognition Program in Gaza, – The New York Times

The Technology section is powered by Favbet Tech The images are matched against a database of Palestinians with ties to Hamas. According to The New York Times,…

Twitch has banned chest and buttock broadcasts of gameplay

Twitch has updated its community rules and banned the focus of streams on breasts and buttocks. According to the update, starting March 29, “content that focuses on…

Leave a Reply

Your email address will not be published. Required fields are marked *