The Apple Vision Pro has already been hacked - Apple says there's nothing to worry about, but security experts disagree

Apple Vision Pro battery pack
(Image credit: Future / Lance Ulanoff)

Apple has already released a security patch for its Vision Pro headset, just one day after reviews were published.

Apple says the vulnerability "may have been exploited" already by hackers, and it concerns the device's Safari web browser engine, WebKit, which would have allowed threat actors to execute malicious code.

The tech giant patched the same flaw last week in the new iOS 17.3, which fixes not just iPhones and iPads, but also Macs and Apple TV. Apple Watch is still without a patch, however.

Already exploited?

TechCrunch asked Apple spokesperson Scott Radcliffe if the hackers used the flaw to target the Vision Pro specifically, but he "would not say."

It isn't known if the flaw was exploited for sure, but WebKit has proved a popular target for threat actors, such as spyware vendors, as it can give access to personal data and the whole operating system

Users are at risk of this flaw when they visit dangerous web domains in their browser or via apps. Numerous patches for WebKit were also rolled out last year by Apple. 

In January 2023, a flaw in the engine could have let hackers take full control of older iPhones and iPads. And in October of the same year, researchers discovered a way to steal passwords and other data from many Apple devices with A- and M- series chips, via Safari on Macs or any browser on iPhone and iPad, since they all rely on WebKit.

Interestingly, despite Apple requiring all browsers on its mobile devices to run on WebKit, Google Chromium engineers have been testing out the Blink engine on iOS, which powers Chrome in other instances, to see how well it would run, perhaps anticipating that Apple will at some point open the doors beyond WebKit. 

MORE FROM TECHRADAR PRO

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Apple Vision Pro Review
Apple Intelligence finally arrives on Vision Pro, but it's the new iOS app that might turn heads
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business