CPATH-2026-0013 · Smart glasses / AR

GAZEploit: keystroke inference from Vision Pro Persona eye movements (CVE-2024-40865)

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsPerception privacy + Account authority

The privacy and account paths are co-dominant at CRITICAL because one outward Persona channel can disclose typed content and, conditionally, credentials that cross into account authority; neither is selected by array order.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Privacy · Co-dominant path

Perception privacy

Sanctioned Persona output carries gaze-correlated motion that can be reconstructed into typed content outside the headset.

CRITICAL
  1. accessSource-backed

    Sanctioned Persona output

    The GAZEploit paper and project demonstrate that ordinary, sanctioned Persona output in video calls exposes avatar eye movements to a remote observer without direct access to headset sensor data.

    EvidenceGAZEploit paper (arXiv:2409.08122) · Project site

  2. boundaryModel inference

    Gaze representation crosses the headset boundary

    Persona faithfully represents gaze-correlated eye movement across the headset boundary; the model treats that outward avatar signal as perception-derived data rather than direct sensor export.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. transitionSource-backed

    Keystroke reconstruction

    The researchers report reconstructing a virtual keyboard layout and inferring keystrokes from the observed Persona gaze sequence.

    EvidenceGAZEploit paper (arXiv:2409.08122) · Project site

  4. consequenceModel inference

    Typed content disclosure

    Inferred keystrokes can disclose private typed content to the remote observer. This path records demonstrated inference capability, not confirmed exploitation in the field.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoverySource-backed

    Patched in visionOS 1.3

    The NVD record identifies a fix in visionOS 1.3; the registry therefore records PATCH_AVAILABLE rather than claiming the condition remains active on updated systems.

    EvidenceNVD

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

An ordinary remote participant can receive the sanctioned Persona avatar output without compromising the Vision Pro headset.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Recovering typed content requires gaze analysis and reconstruction, but the researchers demonstrated a reproducible workflow.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The Apple Vision Pro (visionOS · Persona avatar) interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

The Persona leakage does not directly actuate the headset or create a physical safety effect.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Eye movement represented in the avatar can reveal keystrokes and other intimate interaction signals that the user did not intend to transmit.

Model inference
AuthorityAT 0
No authority gained

Observing gaze-derived output provides no direct account, administrative, or firmware authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

Sanctioned avatar output crosses the gaze-privacy boundary and can be transformed into reconstructed keyboard input.

Model inference
Reuse scaleSR 3
Portable product-class technique

The reconstruction technique is reusable across compatible Persona sessions, though it is not a shared credential or universal key.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

A remote participant can collect the permitted avatar stream without per-device physical access to the target headset.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

VisionOS 1.3 changed the exposed representation; recovery is a software update and verification that affected headsets upgraded.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions. This status is recorded for Apple Vision Pro (visionOS · Persona avatar).

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Eye movement represented in the avatar can reveal keystrokes and other intimate interaction signals that the user did not intend to transmit.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:0/DP:4/AT:0/CH:2/SR:3/SX:4/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Account authority

Reconstructed keystrokes may include passwords or credentials whose successful reuse crosses into account authority.

CRITICAL
  1. accessSource-backed

    Remote Persona observation

    A remote participant can receive the ordinary Persona stream and observe the gaze-correlated avatar motion documented by GAZEploit.

    EvidenceGAZEploit paper (arXiv:2409.08122) · Project site

  2. transitionSource-backed

    Credential reconstruction

    Passwords or other credentials can be recovered from inferred keystrokes; using a valid recovered secret is the additional transition into account authority.

    EvidenceGAZEploit paper (arXiv:2409.08122) · Project site

  3. boundaryModel inference

    Credential use is a separate boundary

    The paper demonstrates keystroke inference, not successful account takeover. Account authority therefore depends on the inferred text containing a usable credential and on that credential remaining valid.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    If those conditions hold, credential reuse can enable unauthorized account access. CRITICAL is a modeled candidate consequence, not evidence that GAZEploit produced an observed takeover.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch and rotate exposed secrets

    With the visionOS 1.3 fix available, recovery is modeled as updating affected systems and separately rotating credentials if prior observation is suspected.

    EvidenceNVD

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

A remote participant receives Persona output through the intended communication channel, so no headset exploit is needed to observe it.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Turning gaze traces into typed strings requires the demonstrated reconstruction pipeline rather than a direct plaintext read.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The Apple Vision Pro (visionOS · Persona avatar) interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

Credential reconstruction does not itself control physical actuation or create a direct safety consequence.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The reconstructed strings can include passwords and other authentication secrets typed while Persona output is shared.

Model inference
AuthorityAT 3
Administrative or command authority

A recovered password can transfer authority to the associated account, but the avatar stream grants no headset administrator rights by itself.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Legitimate avatar output becomes a gaze trace, then a typed credential, and finally a potential account-access bridge.

Model inference
Reuse scaleSR 3
Portable product-class technique

The analysis method can be reused across sessions and users, while each recovered credential remains target-specific.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remote collection can occur through normal Persona sessions without physical access to each headset.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

VisionOS 1.3 patched the representation leak; exposed credentials may still require separate rotation and account review.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions. This status is recorded for Apple Vision Pro (visionOS · Persona avatar).

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. A recovered password can transfer authority to the associated account, but the avatar stream grants no headset administrator rights by itself.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:3/EX:3/PH:0/DP:3/AT:3/CH:3/SR:3/SX:4/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the privacy transition before acting on the band.

Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 5.3 MEDIUMNVD / CNA via NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

TL;DR

The Paths model rates this CRITICAL because the Persona avatar is a faithful inference channel: it re-renders the wearer’s exact eye movements, and gaze-typed text — passwords, PINs, emails, messages — can be reconstructed from avatar video alone. The published 5.3 Medium baseline is retained for source review; the Paths drivers are perception leakage and account-authority consequence.

What it is

Vision Pro renders a Persona whose eyes faithfully reproduce the wearer’s real gaze. Because text entry is gaze-driven (you look at each virtual key), researchers (University of Florida · CertiK Skyfall · Texas Tech) showed that from the outward-facing avatar alone — a FaceTime stream or a recording, no device access — a supervised model recovers the saccades and reconstructs the typed input (~86% precision / 97% recall on detecting typing; effective on message, password, email/URL, and PIN entry across 30 participants). Apple fixed it in visionOS 1.3 by suspending Persona’s eyes while the keyboard is active (CVE-2024-40865).

The detail that matters: Apple already sandboxes raw gaze — apps cannot read eye-tracking data. The protection held. The same information left through the avatar, a sanctioned output nobody had labeled as carrying it. Front door guarded; data shipped out the back.

Published baseline — scope note

The vector is AV:N/AC:L/PR:N/UI:N/S:U/**C:L**/I:N/A:N → 5.3. The suppressor is C:L (Low confidentiality, Integrity/Availability None). Two structural bends:

  1. It scored the channel, not the content. CVSS recorded “some text may leak” as Low disclosure. But the leaked text includes authentication secrets — a recovered password is not low-sensitivity information, it is account authority. FIRST’s confidentiality metric has no way to say “the disclosed data is itself a credential,” so a credential leak and a leaked log line score the same C.
  2. NVD-CWE-noinfo. NVD could not classify the weakness. There is no CWE for “a faithful representation of the user is an inference channel.” The harm is an inference channel — nothing was accessed or corrupted; a legitimate output was inverted. CVSS’s access / integrity / availability ontology has no axis for “the output is a structure-preserving function of the secret.”

Consequence driver

The Paths model highlights #9 (representation / inference-channel leakage) — the avatar is a faithful, invertible function of gaze, so a secret can leave through a sanctioned output without conventional access — and #3 (authority-leak as a weakness class), because credential reconstruction can confer account authority rather than only low-sensitivity disclosure. Scale-of-reuse #1 and the gaze → keystroke → credential → account chain #2 also apply.

Requirement #9 — the case behind it

The medical triptych derived eight requirements. GAZEploit — the registry’s first AR / inference-channel case — is the case behind the ninth, now part of the spec:

Representation / inference-channel leakage. A system’s externally-observable output can be a structure-preserving function (a homomorphism) of a sensitive internal variable; observing the output and inverting it recovers the secret — with no access, no exploit, no breach. Protecting a secret therefore requires protecting every sufficiently-informative function of it, including its rendered, displayed, or physically actuated outputs — not just the variable itself.

CVSS and CWE have no vocabulary for this; Paths’s Perception axis is the closest existing home, and the requirement is now named explicitly (#9). The principled fix is not Apple’s content-specific gate (which plugs keystrokes but leaves reading, attention, and affect leaking) — it is render from intent, not from biology: synthesize a socially-sufficient avatar that conveys presence without mirroring the exact gaze vector. Mirroring is leakage; synthesis is safe.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0013 (“GAZEploit: keystroke inference from Vision Pro Persona eye movements (CVE-2024-40865)”), paths.cfse.ai/CPATH-2026-0013 (published 2026-06-03).