Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Privacy · Co-dominant path
Perception privacy
Sanctioned Persona output carries gaze-correlated motion that can be reconstructed into typed content outside the headset.
Sanctioned Persona output
The GAZEploit paper and project demonstrate that ordinary, sanctioned Persona output in video calls exposes avatar eye movements to a remote observer without direct access to headset sensor data.
Gaze representation crosses the headset boundary
Persona faithfully represents gaze-correlated eye movement across the headset boundary; the model treats that outward avatar signal as perception-derived data rather than direct sensor export.
EvidenceNo direct citation — inspect the declared inference or assumption.
Keystroke reconstruction
The researchers report reconstructing a virtual keyboard layout and inferring keystrokes from the observed Persona gaze sequence.
Typed content disclosure
Inferred keystrokes can disclose private typed content to the remote observer. This path records demonstrated inference capability, not confirmed exploitation in the field.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patched in visionOS 1.3
The NVD record identifies a fix in visionOS 1.3; the registry therefore records PATCH_AVAILABLE rather than claiming the condition remains active on updated systems.
EvidenceNVD
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
An ordinary remote participant can receive the sanctioned Persona avatar output without compromising the Vision Pro headset.
- Execution complexity
EC 3 - Reproducible exploit workflow
Recovering typed content requires gaze analysis and reconstruction, but the researchers demonstrated a reproducible workflow.
- Exposure
EX 3 - Execution effort limits exposure
The Apple Vision Pro (visionOS · Persona avatar) interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 0 - No direct physical effect
The Persona leakage does not directly actuate the headset or create a physical safety effect.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Eye movement represented in the avatar can reveal keystrokes and other intimate interaction signals that the user did not intend to transmit.
- Authority
AT 0 - No authority gained
Observing gaze-derived output provides no direct account, administrative, or firmware authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
Sanctioned avatar output crosses the gaze-privacy boundary and can be transformed into reconstructed keyboard input.
- Reuse scale
SR 3 - Portable product-class technique
The reconstruction technique is reusable across compatible Persona sessions, though it is not a shared credential or universal key.
- Execution scale
SX 4 - Remote fleet-scale execution
A remote participant can collect the permitted avatar stream without per-device physical access to the target headset.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
VisionOS 1.3 changed the exposed representation; recovery is a software update and verification that affected headsets upgraded.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions. This status is recorded for Apple Vision Pro (visionOS · Persona avatar).
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Eye movement represented in the avatar can reveal keystrokes and other intimate interaction signals that the user did not intend to transmit.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_PRIVACY/RE:4/EC:3/EX:3/PH:0/DP:4/AT:0/CH:2/SR:3/SX:4/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →Authority · Co-dominant path
Account authority
Reconstructed keystrokes may include passwords or credentials whose successful reuse crosses into account authority.
Remote Persona observation
A remote participant can receive the ordinary Persona stream and observe the gaze-correlated avatar motion documented by GAZEploit.
Credential reconstruction
Passwords or other credentials can be recovered from inferred keystrokes; using a valid recovered secret is the additional transition into account authority.
Credential use is a separate boundary
The paper demonstrates keystroke inference, not successful account takeover. Account authority therefore depends on the inferred text containing a usable credential and on that credential remaining valid.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
If those conditions hold, credential reuse can enable unauthorized account access. CRITICAL is a modeled candidate consequence, not evidence that GAZEploit produced an observed takeover.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch and rotate exposed secrets
With the visionOS 1.3 fix available, recovery is modeled as updating affected systems and separately rotating credentials if prior observation is suspected.
EvidenceNVD
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
A remote participant receives Persona output through the intended communication channel, so no headset exploit is needed to observe it.
- Execution complexity
EC 3 - Reproducible exploit workflow
Turning gaze traces into typed strings requires the demonstrated reconstruction pipeline rather than a direct plaintext read.
- Exposure
EX 3 - Execution effort limits exposure
The Apple Vision Pro (visionOS · Persona avatar) interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 0 - No direct physical effect
Credential reconstruction does not itself control physical actuation or create a direct safety consequence.
- Data / perception
DP 3 - Sensitive device or personal data
The reconstructed strings can include passwords and other authentication secrets typed while Persona output is shared.
- Authority
AT 3 - Administrative or command authority
A recovered password can transfer authority to the associated account, but the avatar stream grants no headset administrator rights by itself.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Legitimate avatar output becomes a gaze trace, then a typed credential, and finally a potential account-access bridge.
- Reuse scale
SR 3 - Portable product-class technique
The analysis method can be reused across sessions and users, while each recovered credential remains target-specific.
- Execution scale
SX 4 - Remote fleet-scale execution
Remote collection can occur through normal Persona sessions without physical access to each headset.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
VisionOS 1.3 patched the representation leak; exposed credentials may still require separate rotation and account review.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions. This status is recorded for Apple Vision Pro (visionOS · Persona avatar).
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. A recovered password can transfer authority to the associated account, but the avatar stream grants no headset administrator rights by itself.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:4/EC:3/EX:3/PH:0/DP:3/AT:3/CH:3/SR:3/SX:4/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the privacy transition before acting on the band.
Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
- paperGAZEploit paper (arXiv:2409.08122)
GAZEploit paper
- pocProject site
Project site
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCVE recordsCVE-2024-40865
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
TL;DR
The Paths model rates this CRITICAL because the Persona avatar is a faithful inference channel: it re-renders the wearer’s exact eye movements, and gaze-typed text — passwords, PINs, emails, messages — can be reconstructed from avatar video alone. The published 5.3 Medium baseline is retained for source review; the Paths drivers are perception leakage and account-authority consequence.
What it is
Vision Pro renders a Persona whose eyes faithfully reproduce the wearer’s real gaze. Because text entry is gaze-driven (you look at each virtual key), researchers (University of Florida · CertiK Skyfall · Texas Tech) showed that from the outward-facing avatar alone — a FaceTime stream or a recording, no device access — a supervised model recovers the saccades and reconstructs the typed input (~86% precision / 97% recall on detecting typing; effective on message, password, email/URL, and PIN entry across 30 participants). Apple fixed it in visionOS 1.3 by suspending Persona’s eyes while the keyboard is active (CVE-2024-40865).
The detail that matters: Apple already sandboxes raw gaze — apps cannot read eye-tracking data. The protection held. The same information left through the avatar, a sanctioned output nobody had labeled as carrying it. Front door guarded; data shipped out the back.
Published baseline — scope note
The vector is AV:N/AC:L/PR:N/UI:N/S:U/**C:L**/I:N/A:N → 5.3. The suppressor is C:L (Low confidentiality, Integrity/Availability None). Two structural bends:
- It scored the channel, not the content. CVSS recorded “some text may leak” as Low disclosure. But the leaked text includes authentication secrets — a recovered password is not low-sensitivity information, it is account authority. FIRST’s confidentiality metric has no way to say “the disclosed data is itself a credential,” so a credential leak and a leaked log line score the same
C. NVD-CWE-noinfo. NVD could not classify the weakness. There is no CWE for “a faithful representation of the user is an inference channel.” The harm is an inference channel — nothing was accessed or corrupted; a legitimate output was inverted. CVSS’s access / integrity / availability ontology has no axis for “the output is a structure-preserving function of the secret.”
Consequence driver
The Paths model highlights #9 (representation / inference-channel leakage) — the avatar is a faithful, invertible function of gaze, so a secret can leave through a sanctioned output without conventional access — and #3 (authority-leak as a weakness class), because credential reconstruction can confer account authority rather than only low-sensitivity disclosure. Scale-of-reuse #1 and the gaze → keystroke → credential → account chain #2 also apply.
Requirement #9 — the case behind it
The medical triptych derived eight requirements. GAZEploit — the registry’s first AR / inference-channel case — is the case behind the ninth, now part of the spec:
Representation / inference-channel leakage. A system’s externally-observable output can be a structure-preserving function (a homomorphism) of a sensitive internal variable; observing the output and inverting it recovers the secret — with no access, no exploit, no breach. Protecting a secret therefore requires protecting every sufficiently-informative function of it, including its rendered, displayed, or physically actuated outputs — not just the variable itself.
CVSS and CWE have no vocabulary for this; Paths’s Perception axis is the closest existing home, and the requirement is now named explicitly (#9). The principled fix is not Apple’s content-specific gate (which plugs keystrokes but leaves reading, attention, and affect leaking) — it is render from intent, not from biology: synthesize a socially-sufficient avatar that conveys presence without mirroring the exact gaze vector. Mirroring is leakage; synthesis is safe.
Sources
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-40865
- GAZEploit (Wang, Zhan et al.), arXiv:2409.08122 · https://sites.google.com/view/gazeploit/
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0013 (“GAZEploit: keystroke inference from Vision Pro Persona eye movements (CVE-2024-40865)”), paths.cfse.ai/CPATH-2026-0013 (published 2026-06-03).