The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity warning regarding multiple vulnerabilities found in Apple Vision Pro. This device works on the newly developed VisionOS and is susceptible to severe security breaches that could let malicious actors take control of the system, access confidential user information, and cause significant disruptions.
This advisory highlights that these vulnerabilities could be exploited in a number of ways, putting users at risk. One of the critical flaws enables attackers to execute arbitrary code with kernel-level privileges. This will allow hackers to access the system, bypassing most built-in security mechanisms, hence letting them install malicious software or change system settings without detection.
Another big concern is the instability it brings to apps, which might close unexpectedly. This disruption can affect the user experience and potentially result in loss of data. Moreover, the vulnerabilities allow bypassing kernel memory protections, a critical issue as this memory is important for maintaining system stability and security. Attackers can get deeper access to the system by exploiting this flaw, allowing them to take out undetected malicious activities.
Also Read: Apple Watch To Track Sleep Automatically With WatchOS 11
Advisory Warns About User Fingerprinting
The advisory has also warned about the potential for user fingerprinting, which involves tracking and identifying users depending on their device usage. This shows a significant privacy threat as it could lead to unauthorized user profiling and monitoring. Moreover, the vulnerabilities allow hackers to circumvent security restrictions, which nullifies the safeguards designed to protect the system from unauthorized access.
Another critical risk posed by these flaws is the potential for Denial of Service (DoS) attacks, which could render the device inoperable by overwhelming it with several requests.
Hackers could also get access to sensitive data stored on the device, such as personal information, photos, and messages, compromising user privacy. These flaws would also allow attackers to perform actions typically restricted to system administrators, further jeopardizing the device’s security.
Also Read: Which Macs Will And Will Not Get New Apple Intelligence Features
Apple Issues Software Update To Curb Vulnerabilities
According to the government body, the main cause of these flaws stems from several technical issues within VisionOS components. These include ‘use-after-free’ bugs in the kernel, defects in the CoreMedia and libiconv components, and out-of-bounds write and access problems. These issues can be exploited through malicious web content, resulting in memory corruption and system compromise.
Given these significant security concerns, Apple has rolled out a software update for the Vision Pro. CERT-In has advised all users to instantly download and install this update to protect their devices from potential hacks. Keeping your devices up-to-date is important for defending against these vulnerabilities and ensuring the system’s security and integrity.