<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k" -->

---
title: Critical CocoaPods Vulnerabilities Patched to Prevent...
description: Security vulnerabilities in CocoaPods, a popular dependency manager for iOS and macOS apps, have exposed millions of Apple devices to potential supply chain...
canonical: https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical CocoaPods Vulnerabilities Patched to Prevent Supply Chain Attacks | daily.dev
og:description: Security vulnerabilities in CocoaPods, a popular dependency manager for iOS and macOS apps, have exposed millions of Apple devices to potential supply chain...
og:url: https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k
og:image: https://api.daily.dev/og/posts/1Ld9LB27k.png
og:image:alt: Critical CocoaPods Vulnerabilities Patched to Prevent Supply Chain Attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical CocoaPods Vulnerabilities Patched to Prevent Supply Chain Attacks

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 2 upvotes · 1 comments

## Summary

Security vulnerabilities in CocoaPods, a popular dependency manager for iOS and macOS apps, have exposed millions of Apple devices to potential supply chain attacks. Major flaws include unauthorized account ownership of 'orphaned pods' and a remote code execution vulnerability. The CocoaPods team has patched these vulnerabilities, but developers are urged to verify dependencies, use Software Composition Analysis tools, maintain secure update practices, and actively monitor supply chains.

## Content

# Critical Vulnerabilities in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks

Security researchers have uncovered several critical vulnerabilities in CocoaPods, a widely-used dependency manager for iOS and macOS applications. These flaws, some dating back to a 2014 workflow change, have exposed millions of Apple devices to potential supply chain attacks, emphasizing the pressing need for developers to scrutinize their open-source dependencies and enhance governance over these tools.

## Overview of the Vulnerabilities

One of the most severe vulnerabilities, tracked as CVE-2024-38368, involves unauthorized account ownership of 'orphaned pods'—packages that lack active maintenance. This flaw enables attackers to claim these unmaintained pods and potentially inject malicious code into applications that rely on them. Additionally, a remote code execution vulnerability, assigned a perfect CVSS score of 10.0, posed significant risks by allowing malicious actors to execute arbitrary code on CocoaPods servers.

These vulnerabilities collectively threaten the security of countless apps by permitting attackers to take control of packages and embed malware, thereby endangering organizations and end-users alike.

## Mitigation and Response

In response to these threats, the CocoaPods team swiftly patched these vulnerabilities and reset all user sessions to mitigate risks. Despite the lack of evidence indicating these bugs have been exploited in the wild, the pervasive use of CocoaPods in Apple’s ecosystem underscores the need for continued vigilance.

EvaSec, the security firm that disclosed CVE-2024-38368, highlighted several measures for developers to mitigate the impact of such vulnerabilities:

1. **Verify Dependencies:** Regularly audit third-party libraries for orphaned pods and ensure that they are actively maintained.
2. **Use Software Composition Analysis (SCA) Tools:** Implement SCA tools to identify and manage open-source dependencies, helping to detect vulnerabilities early.
3. **Maintain Secure Update Practices:** Keep `podfile.lock` files synchronized and perform thorough security reviews of third-party code before integration.
4. **Monitor Supply Chains:** Actively monitor and govern software supply chains to preemptively catch and resolve security issues.

## Conclusion

The discovery of these vulnerabilities in CocoaPods serves as a stark reminder of the inherent risks within software supply chains. As dependency managers like CocoaPods play a crucial role in modern app development, developers must remain vigilant, consistently validating and securing their dependencies to safeguard against potential supply chain attacks.

## Community discussion

Top comments from developers on daily.dev.

**@murilolodovico** · 0 upvotes

> It's weird that they have this type of problem since 2014.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devops](https://daily.dev/tags/devops), [#ios](https://daily.dev/tags/ios), [#swift](https://daily.dev/tags/swift), [#mac](https://daily.dev/tags/mac)

[View this post on daily.dev](https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical CocoaPods Vulnerabilities Patched to Prevent Supply Chain Attacks","url":"https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k"},"datePublished":"2024-07-01T17:13:49.493Z","dateModified":"2024-07-03T20:14:18.675Z","description":"Security vulnerabilities in CocoaPods, a popular dependency manager for iOS and macOS apps, have exposed millions of Apple devices to potential supply chain...","image":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy4XMLqZptCkn7ifIbKGNRWsYao93PQLI_x3x8VZigNo90bYOFGmw4jFFboOxaUu6Qvb2pXPGk_s6FEaz17DOyhSYIQ2ptN60p6yN5WJHX6I5PoAWaZaCHjJTOnsk3QoGzNOp16Nd8dw9C3RRfC4Pis3Ia0Z9jY5TdQ8anlENDdRuRzNGvjfnKayb-rEMJ/s728-rw-e365/Supply-Chain-Attack.gif","thumbnailUrl":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy4XMLqZptCkn7ifIbKGNRWsYao93PQLI_x3x8VZigNo90bYOFGmw4jFFboOxaUu6Qvb2pXPGk_s6FEaz17DOyhSYIQ2ptN60p6yN5WJHX6I5PoAWaZaCHjJTOnsk3QoGzNOp16Nd8dw9C3RRfC4Pis3Ia0Z9jY5TdQ8anlENDdRuRzNGvjfnKayb-rEMJ/s728-rw-e365/Supply-Chain-Attack.gif","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,devops,ios,swift,mac","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Critical CocoaPods Vulnerabilities Patched to Prevent Supply Chain Attacks"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/critical-cocoapods-vulnerabilities-patched-to-prevent-supply-chain-attacks-1ld9lb27k","comment":[{"@type":"Comment","text":"It’s weird that they have this type of problem since 2014.","datePublished":"2024-07-10T15:19:32.082Z","url":"https://daily.dev/posts/1Ld9LB27k#c-OHhY6yOSM","author":{"@type":"Person","name":"Murilo Lodovico","url":"https://daily.dev/murilolodovico","image":"https://avatars.githubusercontent.com/u/37813008?v=4"}}]}
```

