logo

Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks

ID: 557a4a15-e45f-57ff-ab29-f47737146a5d

STIX ID: report--557a4a15-e45f-57ff-ab29-f47737146a5d

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-07-01

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed three critical vulnerabilities in CocoaPods that let attackers claim thousands of unclaimed pods, achieve remote code execution on the Trunk server, and steal developer session tokens via a flawed email verification workflow; combined, these weaknesses could enable large-scale iOS/macOS supply-chain attacks. The issues (notably CVE-2024-38366 with a 10.0 CVSS) were reported and patched in October 2023, and maintainers reset user sessions in response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.