Vietnam.vn - Nền tảng quảng bá Việt Nam

Warning: Dangerous vulnerability attacks the iOS operating system.

Báo Kinh tế và Đô thịBáo Kinh tế và Đô thị03/07/2024


EVA Information Security, a cybersecurity and testing company based in Israel, has discovered a vulnerability in Cocoapods, a widely used dependency manager for software projects coded in Swift and Objective-C.

Dependency Managers are crucial tools in software development, enabling validation and cryptographic signing of software packages. Therefore, problems with such a tool can negatively impact many parts of the software or website.

Thousands of iOS apps could be at risk due to an open-source vulnerability.
Thousands of iOS apps could be at risk due to an open-source vulnerability.

According to EVA Information Security, the problem may have existed since 2014, resulting from a clumsy migration of Cocoapods servers that caused thousands of software library packages to lose their original source code and become untraceable. This vulnerability allowed attackers to replace the original source code with their own malicious code.

A company representative stated: "Due to system security flaws, these packages could be hijacked by malicious actors and then used to inject malware into software development tools for developers. Because they went undetected for so long, this means thousands of applications and millions of devices have been exposed over the years."

With many applications having access to sensitive user information such as credit card details, medical records, and private documents, hackers can exploit vulnerabilities to install ransomware or other malware to collect this information.

EVA Information Security argues that Apple is "at the center of the mess" as the majority of iOS and macOS applications are coded using Swift and Objective-C, including popular names like TikTok, Snapchat, LinkedIn, Netflix, Microsoft Teams, Facebook, and Messenger.

Therefore, thousands of applications on these platforms could be affected. An attack on the mobile app ecosystem could infect most Apple devices, leaving thousands of organizations vulnerable financially and in terms of reputation.

Reportedly, these vulnerabilities have now been patched by Cocoapods, but the fact that they went undetected for nearly a decade is concerning. EVA Information Security advises developers to review their product source code to determine if their software is affected by these flaws.

Apple has not yet commented on the news.



Source: https://kinhtedothi.vn/canh-bao-lo-hong-nguy-hiem-tan-cong-he-dieu-hanh-ios.html

Tag: POISON

Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

A close-up view of the workshop making the LED star for Notre Dame Cathedral.
The 8-meter-tall Christmas star illuminating Notre Dame Cathedral in Ho Chi Minh City is particularly striking.
Huynh Nhu makes history at the SEA Games: A record that will be very difficult to break.
The stunning church on Highway 51 lit up for Christmas, attracting the attention of everyone passing by.

Same author

Heritage

Figure

Enterprise

Farmers in Sa Dec flower village are busy tending to their flowers in preparation for the Festival and Tet (Lunar New Year) 2026.

News

Political System

Destination

Product