Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks
ID: 557a4a15-e45f-57ff-ab29-f47737146a5d
STIX ID: report--557a4a15-e45f-57ff-ab29-f47737146a5d
Feed Name: The Hacker News
Threat Score
Researchers disclosed three critical vulnerabilities in CocoaPods that let attackers claim thousands of unclaimed pods, achieve remote code execution on the Trunk server, and steal developer session tokens via a flawed email verification workflow; combined, these weaknesses could enable large-scale iOS/macOS supply-chain attacks. The issues (notably CVE-2024-38366 with a 10.0 CVSS) were reported and patched in October 2023, and maintainers reset user sessions in response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
