π¨Zer0 Day Hell !π¨ 10-Year-Old Open Source Flaws Could Affect Almost Every Apple Device due to crappy shared common source code used by novices and DIVERSITY Hires! π¨ Facebook, Whatsapp Safari, AppleTV, Xcode Microsoft Teams, TikTok, Snapchat, Amazon, LinkedIn, Netflix, Okta, Yahoo, Zynga!π¨
original content (evasec.webflow.io)https://evasec.webflow.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods WARNING TO ALL USERS ON VOAT! TODAY YOU CAN POSSIBLY STILL BE INVADED from 2014 to tonight!
2024.07.02 : This set of exploits affects almost all Apple users that use software written by large companies with a couple
token diversity hire novice engineers who "reuse" public domain source code example routines.
https://evasec.webflow.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods https://thecyberexpress.com/cocoapods-vulnerabilities-apple-facebook/ https://www.cvedetails.com/cve/CVE-2024-38366/ CVE-2024-38366 received a 10 out of 10 criticality score -- actually date from a May 2014 to today
Naturally, one exploit was used to create many more since 2014.
BEWARE APPS ON YOUR APPLE DEVICES THIS WEEK!