The advisory from CERT-In highlights that these vulnerabilities could be exploited in various ways, posing significant security risks
India’s Computer Emergency Response Team (CERT-In) has issued a high-severity warning about multiple security vulnerabilities in Apple’s Vision Pro, the company’s latest and most expensive device. Running on the new VisionOS, the Vision Pro is at risk of serious security breaches due to flaws that could allow attackers to take control of the system, access sensitive user data, and cause significant disruptions.
The advisory from CERT-In highlights that these vulnerabilities could be exploited in various ways, posing significant security risks. An attacker could potentially execute arbitrary code with kernel privileges, granting them the highest level of access to the system and enabling them to bypass most built-in security measures. This could result in unauthorised control over the device, allowing the attacker to install malicious software or change system settings without detection.
Another critical issue identified is the potential for apps to crash unexpectedly, disrupting the user experience and possibly leading to data loss. The vulnerabilities also permit bypassing kernel memory protections, which are vital for maintaining system stability and security. Exploiting this flaw could give attackers deeper access to the system, enabling malicious activities to go undetected.
In addition, the flaws allow for user fingerprinting, meaning attackers could track and identify users based on their device usage. This poses significant privacy concerns, as it could lead to unauthorised profiling and monitoring of users. The vulnerabilities also enable attackers to bypass security restrictions, undermining the safeguards designed to protect the system from unauthorised access.
Furthermore, these vulnerabilities can lead to Denial of Service (DoS) attacks, making the device inoperable by overwhelming it with excessive requests or exploiting specific weaknesses to cause crashes. Attackers could also access sensitive information stored on the device, such as personal data, photos, and messages, putting user privacy at serious risk. Elevated privileges gained through these vulnerabilities would allow attackers to perform actions usually restricted to system administrators, further compromising the device’s security.
The root causes of these vulnerabilities are traced back to various technical issues within VisionOS components. These include ‘use-after-free’ bugs in the kernel, errors in the CoreMedia and libiconv components, out-of-bounds write and access issues, integer overflows, and type confusion errors in the WebKit component. Attackers could exploit these technical flaws through maliciously crafted web content, leading to memory corruption and system compromise.
In response to these serious security concerns, Apple has released a software update for the Vision Pro. CERT-In advises all users to promptly download and install this update to protect their devices from potential exploits. Keeping the software up to date is crucial in safeguarding against these vulnerabilities and ensuring the system’s security and integrity.

