logo

Apple CocoaPods Bugs Expose Millions of Apps to Code Injection

ID: 5ba6053c-f6f1-5af1-9e4a-672fb1e3d6ea

STIX ID: report--5ba6053c-f6f1-5af1-9e4a-672fb1e3d6ea

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-07-01

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

E.V.A Information Security found several critical vulnerabilities in CocoaPods' Trunk service — notably a CVE-2024-38366 RCE via a vulnerable RubyGem and bugs allowing orphaned pod takeover and session hijacking — that potentially allowed attackers to modify or inject malicious code into widely used iOS/macOS libraries; the flaws date back to a 2014 migration and could have affected thousands of pods and millions of apps, though CocoaPods patched the issues in October and there is no clear evidence of exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.