logo

Apple NSXMLParser XXE Vulnerability Exposed

ID: 3fd8113c-27b3-5f43-87cc-e4d2d41dc2d6

STIX ID: report--3fd8113c-27b3-5f43-87cc-e4d2d41dc2d6

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2025-12-02

Date Updated: 2026-08-01

...
...

Virtual Security Research disclosed a high-severity XML External Entity (XXE) vulnerability in Apple's NSXMLParser affecting iOS 7.0/7.1 and OS X 10.9.x, demonstrating that external entities were resolved by default (and disabling did not work), providing PoC code and server/DNS logs, and recommending updates to iOS 8/OS X 10.9.5 which contain the fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.