News

Three million macOS, iOS apps were exposed to supply chain attacks

Vulnerabilities that went undetected for a decade left thousands of macOS and iOS apps susceptible to supply-chain attacks. According to ArsTechnica, hackers could have added malicious code compromising the security of millions or billions of people who installed them.

The vulnerabilities, which were fixed last October, resided in a “trunk” server used to manage CocoaPods, a repository for open source Swift and Objective-C projects that roughly 3 million macOS and iOS apps depend on. When developers make changes to one of their “pods”—CocoaPods lingo for individual code packages—dependent apps typically incorporate them automatically through app updates, typically with no interaction required by end users.

“Many applications can access a user’s most sensitive information: credit card details, medical records, private materials, and more,” wrote researchers from EVA Information Security, the firm that discovered the vulnerability. “Injecting code into these applications could enable attackers to access this information for almost any malicious purpose imaginable—ransomware, fraud, blackmail, corporate espionage… In the process, it could expose companies to major legal liabilities and reputational risk.”

The firm added that, “While there is no direct evidence of any of these vulnerabilities being exploited in the wild, evidence of absence is not absence of evidence. Potential code changes could affect millions of Apple devices around the world across iPhone, Mac, AppleTV, and AppleWatch devices.”

Dennis Sellers

Dennis Sellers is the editor/publisher of Apple World Today. He’s been an “Apple journalist” since 1995 (starting with the first big Apple news site, MacCentral). He loves to read, run, play sports, and watch movies.

Recent Posts

Apple approves Epic Games’s marketplace app on iPhones, iPads in Europe

Apple has approved Epic Games' games marketplace app on iPhones and iPads in Europe, reports…

4 hours ago

Apple Original Films’ Formula 1 movie will be titled ‘F1’

A year before debuting the Joseph Kosinski-directed, Brad Pitt-starring Formula 1 movie, Apple Original Film…

7 hours ago

Apple’s lucrative Internet search engine deal with Google may be in trouble

Apple’s (very) lucrative deal with Google that makes it the default search engine on Safari…

7 hours ago

Apple may indeed be working on a HomePod with a display

Apple may indeed be working on the long-rumored HomePod with a display.

12 hours ago

Apple removes mobile apps of 25 VPN services from its App Store in Russia

Apple has removed the mobile apps of 25 VPN services from its App Store, following…

14 hours ago

iPhone 16 Pro may get a tetra prism periscope camera with 5x optical zoom

The iPhone 16 Pro will gain the tetraprism periscope camera with 5x optical zoom that…

14 hours ago