Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks
Three security vulnerabilities have been found in the CocoaPods dependency management for the Objective-C and Swift Cocoa projects. These vulnerabilities might be used to stage software supply chain assaults, which would pose a serious danger to downstream customers.
Researchers Reef Spektor and Eran Vaknin of E.V.A Information Security stated in a paper released today that the vulnerabilities enable "any malicious actor to claim ownership over thousands of unclaimed pods and insert malicious code into many of the most popular iOS and macOS applications."
The three vulnerabilities have reportedly been fixed by CocoaPods as of October 2023, according to the Israeli application security company. In reaction to the disclosures, it also resets all user sessions at that particular time r...

