Three security issues were found in CocoaPods, the dependency manager for Swift and Objective‑C projects.

These problems could be used for attacks on the supplychain, putting customers at serious risk.
The vulnerabilities allow malicious actors to gain control of thousands of unauthorized pods and inject malicious code into many of the most popular iOS and macOS, according to EVA Information Security researchers Reef Spektor and Eran Vaknin, in a report published today.
Read also: What are the vulnerabilities of the OAS platform?
The Israeli application security company reported that the three issues have been fixed by CocoaPods since October 2023 and that all user operation periods have resumed.
One of the vulnerabilities, codenamed CVE-2024-38368 and rated CVSS 9.3, allows a hacker to click “Claim Your Pods” to gain control. This gives them the ability to modify the source code and introduce malicious changes. However, for this to happen, all previous maintainers must first be removed from the project.
The roots of the problem date back to 2014, when a migration to the Trunk server left thousands of packages without authorized owners. This allowed a hacker to leverage a public API and access pods using an email address from the CocoaPods source code (“unclaimed-pods@cocoapods.org”), thereby taking control of the system.
The second flaw, codenamed CVE-2024-38366 and rated CVSS 10.0, is even more critical. It exploits an insecure email verification process to execute arbitrary code on the Trunk server, which could be used to manipulate or replace packets.
See also: HP: Three serious vulnerabilities affect hundreds of printers
Another issue was found in the service, specifically in the email address verification system (CVE-2024-38367, CVSS score: 8.2). This issue could trick a recipient into clicking on a seemingly innocent verification link, which in fact redirects the request to a domain controlled by hackers, with the aim of accessing a developer's session tokens.
This could escalate to an account takeover attack without any user action, by forging an HTTP header – that is, modifying the X-Forwarded-Host header field – and exploiting misconfigured email security tools
«We found that almost all pod owners are registered on the Trunk server with their organization's email, a fact that makes them vulnerable to the vulnerability», the researchers said.

Read more: Two critical vulnerabilities in Samsung Galaxy S21 smartphones
This isn't the first time CocoaPods has been under the microscope. In March 2023, Checkmarx revealed that a sub-domain associated with the dependency manager (“cdn2.cocoapods[.]org”) could have been compromised by hackers via GitHub pages, with the aim of hosting malicious payloads.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews
