'Almost every Apple device' vulnerable to CocoaPods supply chain attack
ID: 3538ce94-8a05-55af-a451-2326b5c4fae1
STIX ID: report--3538ce94-8a05-55af-a451-2326b5c4fae1
Feed Name: The Register (Security)
Security researchers discovered multiple severe vulnerabilities in CocoaPods that allowed attackers to claim unowned packages, remotely execute code on the Trunk server, and perform zero-click account/session takeovers via email-scanning behavior; thousands of pods were orphaned and used by many popular apps, creating a material supply-chain risk. CocoaPods maintainers have applied patches and rotated session keys, and researchers reported no confirmed in-the-wild exploitation, but the potential scale and severity made the issue critical to address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
