Researchers Pull a Vision Pro Passcode Attack a Day After Posting It, Saying the Vendor Wants More Time

A research paper showing that a CAMERA ACROSS THE ROOM can help GUESS an Apple VISION PRO PASSCODE was posted to arXiv on September 28, then WITHDRAWN less than a DAY later. The withdrawal note gives ONE reason: “The vendor requests more time to review our responsible disclosure.” The first version, which names Apple as the platform tested and says the authors filed a SECURITY REPORT with Apple, is STILL readable on arXiv.

Apple Vision Pro resting on a table
Apple Vision Pro, the only headset the GAZEleak authors tested. Photo: Wikimedia Commons.

What the attack claims

The paper, titled GAZEleak: Passcode Inference Against Eye-tracking XR Devices Through External Observation, is by Hwanjo Heo, Junhee Lee and Jinwoo Kim. Its premise targets an ASSUMPTION baked into gaze-as-pointer headsets: because the display and the eye tracker sit INSIDE the device, a bystander supposedly CANNOT see what the wearer is selecting. The authors argue that the HEAD gives the EYES away. Each gaze shift recruits a SMALL, target-dependent head movement, and those sub-degree changes can be recovered from ORDINARY video.

The threat model is strictly PHYSICAL. The attacker installs NO SOFTWARE on the headset and ONLY FILMS the wearer, for example with a phone, a laptop webcam or a surveillance camera. The pinch that confirms each digit marks the TIMING; the head motion between pinches suggests the DIRECTION of travel across the keypad.

The numbers, and how small the test was

The team built a visionOS app that copied the size and layout of the system passcode keypad, then recorded THREE subjects, ALL of them AUTHORS, head-on at 4K and 30 frames per second. Across 18 six-digit test codes, the cross-person method placed the TRUE CODE inside its top ten guesses for 10 of them, or 56 PERCENT. The within-person method managed NINE of 18. The authors chose ten guesses because, per the paper, Vision Pro allows TEN failed attempts before LOCKOUT.

The spread between people is the most IMPORTANT CAVEAT. For one subject, EVERY test code landed in the top ten. For another, the hit rate was 50% within-person and 67% cross-person. For the third, NONE did, although the median guess rank of 12,786 still beat the 500,000 an uninformed ordering would produce. The paper says recovery held down to 540p and 6 frames per second, degraded at 270p, and COLLAPSED at 2 frames per second, which suggests an ORDINARY 1080p camera would be ENOUGH.

  • Device tested: Apple Vision Pro only, with data collected on visionOS 2.5.
  • Subjects: three authors who KNEW the hypothesis, which the paper CONCEDES could BIAS head motion either way.
  • Viewpoint: FRONTAL only; side, rear and partially blocked views were NOT evaluated.
  • Task: NUMERIC passcodes ONLY, not passwords, one-time codes or text.

Why a patch is not the obvious answer

The authors separate GAZEleak from earlier work they cite, including GAZEploit, which inferred gaze from a Vision Pro Persona’s animated eyes during video calls, and TyPose, which read keyboard input from head-pose telemetry. Those leaks ran THROUGH SOFTWARE channels. GAZEleak relies on BIOMECHANICS, and the paper says a vendor “cannot completely suppress it without redesigning gaze interaction itself.”

TWO mitigations are PROPOSED. One shrinks the passcode keypad into a SMALL angular region so the EYES can do the work WITHOUT the HEAD. The other RANDOMIZES the keypad layout during sensitive entry. BOTH carry COSTS the authors acknowledge: more selection errors, slower entry, lost motor memory and a heavier accessibility burden for users with tremor or reduced acuity. They call robust mitigation an OPEN problem.

Apple Vision Pro demo unit in an Apple Store in Nagoya
Gaze-and-pinch input is the default way to enter a Vision Pro passcode. Photo: Wikimedia Commons.

What the withdrawal does and does not mean

The arXiv listing shows version 1 posted at 12:38 UTC on September 28 and version 2, marked withdrawn, at 05:41 UTC on September 29. The withdrawal note does NOT NAME the vendor, and NO public Apple STATEMENT accompanies it. The first version STILL lists the paper for WPES ’26, a privacy workshop scheduled for November 15 to 19 in The Hague.

The paper itself WARNS against reading the result as a flaw UNIQUE to Apple. It says the leak comes from gaze-coupled head motion and may affect ANY system that uses gaze to pick spatially separated targets. That MATTERS beyond Vision Pro. UploadVR reports that Meta’s latest Horizon OS 2.9 test build redesigns window controls around the GAZE input coming with Meta VR Glasses. The GAZEleak authors did NOT TEST that hardware or any other headset.

The bottom line: this is PRELIMINARY evidence from three informed subjects, one device and one camera angle, not a DEMONSTRATED real-world EXPLOIT. It is still a CREDIBLE signal that “the screen is inside the headset” is NOT a COMPLETE privacy model for gaze input, and that headset makers may NEED a passcode entry mode designed for a room where someone could be FILMING. The authors say an IRB-approved study with more participants and more camera angles is PLANNED.

Sources: GAZEleak paper, version 1 (Heo, Lee and Kim, arXiv); arXiv submission history and withdrawal note; UploadVR on Horizon OS 2.9 PTC.

Leave a Comment