All vulnerabilities
HIGHSupply chainexploited in the wild

SC-XCODEGHOST-2015

Build system · Xcode (compromised compiler)

Summary

Disclosed in September 2015, XcodeGhost was a counterfeit version of Apple's Xcode IDE distributed via third-party Chinese mirrors that downloaded faster than Apple's official servers. The tampered compiler silently injected malicious code into any iOS app built with it, which then passed App Store review. Court documents later revealed 128 million users (including 18 million in the US) downloaded more than 2,500 affected apps, including WeChat, Didi and CamCard. The malware could read/write the clipboard, open URLs and exfiltrate device data to command-and-control servers.

References

Related vulnerabilities

All Supply chain →