Vietnam.vn - Nền tảng quảng bá Việt Nam

Warning of dangerous vulnerabilities attacking iOS operating system

Báo Kinh tế và Đô thịBáo Kinh tế và Đô thị03/07/2024


Israel-based cybersecurity and testing company EVA Information Security has discovered a bug in Cocoapods, a widely used dependency manager for software projects coded in the Swift and Objective-C programming languages.

Dependency Manager is an important tool in software development, allowing for the validation and cryptographic signing of software packages. Therefore, a problem with such a tool can have a negative impact on many parts of the software or web.

Thousands of iOS apps could be at risk due to open source vulnerability.
Thousands of iOS apps could be at risk due to open source vulnerability.

According to EVA Information Security, the issue may have existed since 2014, and is the result of a botched Cocoapods server migration that left thousands of software library packages unlinked to their original source files and unable to trace their origins. This is a loophole that allows attackers to replace the original source code with their own malicious code.

"Due to system security shortcomings, these packages can be hijacked by bad guys and then used to inject malware into software development tools for developers. Because they were not detected for a long time, it means that thousands of applications and millions of devices have been exposed over the years," the company's representative said.

With many apps having access to sensitive user information like credit cards, medical records, and private documents, hackers can exploit vulnerabilities, install ransomware, or other types of malware to collect them.

EVA Information Security believes that Apple is "at the center of the mess" when most iOS and macOS applications are coded in Swift and Objective-C languages, including popular names such as TikTok, Snapchat, LinkedIn, Netflix, Microsoft Teams, Facebook, Messenger.

As a result, thousands of apps on these platforms could be affected. An attack on the mobile app ecosystem could infect most Apple devices, leaving thousands of organizations vulnerable financially and reputationally.

The bugs have reportedly been patched by Cocoapods, but the fact that they went undiscovered for nearly a decade is a cause for concern. EVA Information Security recommends that developers review their product's source code to determine if their software is vulnerable.

Apple has not yet commented on the news.



Source: https://kinhtedothi.vn/canh-bao-lo-hong-nguy-hiem-tan-cong-he-dieu-hanh-ios.html

Tag: MALICO

Comment (0)

No data
No data
PIECES of HUE - Pieces of Hue
Magical scene on the 'upside down bowl' tea hill in Phu Tho
3 islands in the Central region are likened to Maldives, attracting tourists in the summer
Watch the sparkling Quy Nhon coastal city of Gia Lai at night
Image of terraced fields in Phu Tho, gently sloping, bright and beautiful like mirrors before the planting season
Z121 Factory is ready for the International Fireworks Final Night
Famous travel magazine praises Son Doong cave as 'the most magnificent on the planet'
Mysterious cave attracts Western tourists, likened to 'Phong Nha cave' in Thanh Hoa
Discover the poetic beauty of Vinh Hy Bay
How is the most expensive tea in Hanoi, priced at over 10 million VND/kg, processed?

Heritage

Figure

Business

No videos available

News

Political System

Local

Product