SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
30 stars 0 forks source link

[RegisterSec] 'Almost every Apple device' vulnerable to CocoaPods supply chain attack #30628

Open github-actions[bot] opened 2 days ago

github-actions[bot] commented 2 days ago

Dependency manager used in millions of apps leaves a bitter taste

CocoaPods, an open-source dependency manager used in over three million applications coded in Swift and Objective-C, left thousands of packages exposed and ready for takeover for nearly a decade – thereby creating opportunities for supply chain attacks on iOS and macOS apps, according to security researchers.…

https://go.theregister.com/feed/www.theregister.com/2024/07/02/cocoapods_vulns_supply_chain_potential/