Apple fixes WebKit bug that let hackers run malicious code with visionOS 1.0.2. The company had already patched the issue in iOS 17.3.

Apple fixes WebKit bug that let hackers run malicious code with visionOS 1.0.2. The company had already patched the issue in iOS 17.3.

  • Apple released a security patch for the Vision Pro mixed reality headset to fix a vulnerability in WebKit that "may have been exploited" by hackers in the wild.

  • The vulnerability, officially tracked as CVE-2024-23222, was also patched last week in iOS 17.3 for iPhones, iPads, Macs, and Apple TV.

  • It's not clear if malicious hackers used the vulnerability to specifically exploit the Vision Pro, or who was exploiting it and for what reason.

  • WebKit bugs can be exploited when a victim visits a malicious domain in their browser or the in-app browser.

  • Apple rolled out several patches for WebKit bugs last year.

  • Vision Pro is expected to be available starting Friday.