XcodesOrg / XcodesOrg/XcodesApp
Security Risk: Arbitrary Download
Nobody has claimed this yet.
- Dominant language
- Swift
- Stars
- 8.6k
- Forks
- 387
- Avg merge
- 6d 7h
- Merged PRs (30d)
- 3
Description
Describe the bug
I haven't created a proof-of-concept for the bug yet, but looking at some files, it appears that any unsandboxed application is able to modify the json that Xcodes saves offline to load on launch. They could then change the download url to be a modified Xcode or something else entirely allowing Xcodes to load malware onto the system without a user's knowledge.
I would have to look a lot deeper, but I wonder if a malformed file could also lead to privilege escalation via the helper tool.
@MattKiazyk I don't want to scare anyone or publish too many details publicly without a fix. How should we proceed? Am I wrong? Should I make a proof of concept for the downloading update?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no files or tests. Start by locating the offline JSON loading and download/update paths, then verify whether an unsandboxed application can alter the saved URL and whether the helper tool changes the impact; done means the risk is confirmed or disproven and a remediation scope is agreed.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos, swift
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100