Apple NSXMLParser XXE Vulnerability Exposed
ID: 3fd8113c-27b3-5f43-87cc-e4d2d41dc2d6
STIX ID: report--3fd8113c-27b3-5f43-87cc-e4d2d41dc2d6
Feed Name: NCC Research
Threat Score
Virtual Security Research disclosed a high-severity XML External Entity (XXE) vulnerability in Apple's NSXMLParser affecting iOS 7.0/7.1 and OS X 10.9.x, demonstrating that external entities were resolved by default (and disabling did not work), providing PoC code and server/DNS logs, and recommending updates to iOS 8/OS X 10.9.5 which contain the fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
