GAZEploit: Remote Keystroke Inference Attack by Gaze Estimation from Avatar Views in VR/MR Devices
Hanqiu Wang, Zihao Zhan, Haoqi Shan, Siqi Dai, Maximillian Panoff, Shuo Wang
Abstract
The advent and growing popularity of Virtual Reality (VR) and Mixed Reality (MR) solutions have revolutionized the way we interact with digital platforms. The cutting-edge gaze-controlled typing methods, now prevalent in high-end models of these devices, e.g., Apple Vision Pro, have not only improved user experience but also mitigated traditional keystroke inference attacks that relied on hand gestures, head movements and acoustic side-channels. However, this advancement has paradoxically given birth to a new, potentially more insidious cyber threat, GAZEploit. In this paper, we unveil GAZEploit, a novel eye-tracking based attack specifically designed to exploit these eye-tracking information by leveraging the common use of virtual appearances in VR applications. This widespread usage significantly enhances the practicality and feasibility of our attack compared to existing methods. GAZEploit takes advantage of this vulnerability to remotely extract gaze estimations and steal sensitive keystroke information across various typing scenarios-including messages, passwords, URLs, emails, and passcodes. Our research, involving 30 participants, achieved over 80% accuracy in keystroke inference. Alarmingly, our study also identified over 15 top-rated apps in the Apple Store as vulnerable to the GAZEploit attack, emphasizing the urgent need for bolstered security measures for this state-of-the-art VR/MR text entry method. CCS CONCEPTS • Security and privacy → Privacy protections; Domain-specific security and privacy architectures; • Human-centered computing → Virtual reality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0c8076d7-4de3-40b6-bd7b-c5d2f8ab2285Cited by top-tier papers9
- Side-channel Inference of User Activities in AR/VR Using GPU ProfilingSeonghun Son, Chandrika Mukherjee, Reham Mohamed Aburas, Berk Gülmezoglu et al.NDSS 2026 · 4 citations
- Motion in the Clear: Reconstructing VR User Behavior from Network TrafficJiHo Lee, JinYi Yoon, Taejoong Chung, Brendan David-John et al.USENIX Security 2026
- Omniscience for the Masses: New Threats in the Metaverse's Democratized World CreationAndrea Mengascini, Ryan Aurelio, Jason Polakis, Giancarlo PellegrinoCCS 2026
- Watch and Crack: Password Inference from Smart-Glasses VideoYoav Orenbach, Avishai WoolCCS 2026
- From Perception to Protection: A Developer-Centered Study of Security and Privacy Threats in Extended Reality (XR)Kunlin Cai, Jinghuai Zhang, Ying Li, Zhiyuan Wang et al.NDSS 2026
Builds on10
- VR-Spy: A Side-Channel Attack on Virtual Key-Logging in VR HeadsetsAbdullah Al Arafat, Zhishan Guo, Amro AwadIEEE VR 2021 · 70 citations
- EyeTell: Video-Assisted Touchscreen Keystroke Inference from Eye MovementsYimin Chen, Tao Li, Rui Zhang, Yanchao Zhang et al.S&P 2018 · 60 citations
- A Keylogging Inference Attack on Air-Tapping Keyboards in Virtual EnvironmentsÜlkü Meteriz-Yildiran, Necip Fazil Yildiran, Amro Awad, David MohaisenIEEE VR 2022 · 40 citations
- HoloLogger: Keystroke Inference on Mixed Reality Head Mounted DisplaysShiqing Luo, Xinyu Hu, Zhisheng YanIEEE VR 2022 · 30 citations
- Eavesdropping on Controller Acoustic Emanation for Keystroke Inference Attack in Virtual RealityShiqing Luo, Anh Nguyen, Hafsa Farooq, Kun Sun et al.NDSS 2024
Related papers
- Can Virtual Reality Protect Users from Keystroke Inference Attacks?Zhuolin Yang, Zain Sarwar, Iris Hwang, Ronik Bhaskar et al.USENIX Security 2024 · 26 citations
- Going through the motions: AR/VR keylogging from user head motionsCarter Slocum, Yicheng Zhang, Nael B. Abu-Ghazaleh, Jiasi ChenUSENIX Security 2023
- XR Devices Send WiFi Packets When They Should Not: Cross-Building Keylogging Attacks via Non-Cooperative Wireless SensingChristopher Vattheuer, Justin Feng, Hossein Khalili, Nader Sehatbakhsh et al.NDSS 2026 · 1 citation
- Non-intrusive and Unconstrained Keystroke Inference in VR Platforms via Infrared Side ChannelTao Ni, Yuefeng Du, Qingchuan Zhao, Cong WangNDSS 2025
- Remote Keylogging Attacks in Multi-user VR ApplicationsZihao Su, Kunlin Cai, Reuben Beeler, Lukas Dresel et al.USENIX Security 2024 · 13 citations
