HomeSecurityMalicious content delivered via Apple Podcasts?

Delivery of malicious content via Apple Podcasts?

Security researchers have identified suspicious activity in the Apple Podcasts app, which could be used to deliver malicious content to users (according to a report by Joseph Cox of 404Media).

Apple Podcasts

Cox's report describes some strange experiences with the Podcasts app that certainly suggest something is amiss on both the iOS and macOS versions. He says that over the past few months, the app has been opening automatically and, at times, displaying unusual podcasts without his intervention. According to him, the app (on both Mac and iPhone) has been opening religion, spirituality, and education podcasts for no apparent reason, in some cases even when Cox has unlocked his device.

See also: Guest access to Teams can remove Defender protection

The podcasts, mentioned, often include strange titles containing code fragments, URLs, and in some cases, attempted cross-site scripting attacks.

Delivery of malicious content via Apple Podcasts?
Delivery of malicious content via Apple Podcasts?

Objective-See security expert Patrick Wardle told Cox that he was able to replicate similar behavior, but in his case via a web page. “ Simply visiting a web page is enough to trigger the Apple Podcasts app to open (and load a podcast of the attacker’s choosing), and unlike other external app launchers on macOS, no prompt or approval is required from the user ,” Wardle told 404 Media.

See also: Abandoned iCalendar Sync Domains – 4 million devices at risk

Apple Podcasts: Example of malicious content

One particularly disturbing podcast includes a link that redirects to a website that attempts to perform an XSS attack – a technique in which attackers inject malicious code into legitimate-looking websites. When someone visits the website, a pop-up window appears acknowledging the XSS attempt.

Delivery of malicious content via Apple Podcasts?

Wardle notes that while this behavior isn't directly dangerous in itself, it creates an effective delivery mechanism if there are vulnerabilities in the Podcasts app. "It appears that attackers are actively evaluating the Podcasts app as a potential target," he said.

See also: Risks of using Google Antigravity for app developers

The situation is reminiscent of reports of spam attacks on Google Calendar from a few years ago, where malicious users added unwanted events containing links or promotional content to users' calendars.

Apple did not respond to Cox's multiple requests for comment on the matter.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS