logo

'Almost every Apple device' vulnerable to CocoaPods supply chain attack

ID: 3538ce94-8a05-55af-a451-2326b5c4fae1

STIX ID: report--3538ce94-8a05-55af-a451-2326b5c4fae1

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-07-02

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

Security researchers discovered multiple severe vulnerabilities in CocoaPods that allowed attackers to claim unowned packages, remotely execute code on the Trunk server, and perform zero-click account/session takeovers via email-scanning behavior; thousands of pods were orphaned and used by many popular apps, creating a material supply-chain risk. CocoaPods maintainers have applied patches and rotated session keys, and researchers reported no confirmed in-the-wild exploitation, but the potential scale and severity made the issue critical to address.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.