CVE-2024-40865

MEDIUM

visionOS < 1.3 - Unauthenticated Input Inference via Persona and Virtual Keyboard

Title source: llm
STIX 2.1

Description

The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0038
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

Status published
Products (2)
apple/visionos < 1.3
Apple/visionOS < 1.3
Published Sep 06, 2024
Tracked Since Feb 18, 2026