The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
References
History

Thu, 19 Sep 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple visionos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple
Apple visionos
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Fri, 06 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 01:30:00 +0000

Type Values Removed Values Added
Description The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2024-09-06T01:23:53.981Z

Updated: 2024-10-30T14:32:52.890Z

Reserved: 2024-07-10T17:11:04.715Z

Link: CVE-2024-40865

cve-icon Vulnrichment

Updated: 2024-09-06T13:17:10.157Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-06T02:15:02.297

Modified: 2024-09-19T17:58:37.370

Link: CVE-2024-40865

cve-icon Redhat

No data.