Skip to content

Security Risk: Arbitrary Download #734

@Mcrich23

Description

@Mcrich23

Describe the bug
I haven't created a proof-of-concept for the bug yet, but looking at some files, it appears that any unsandboxed application is able to modify the json that Xcodes saves offline to load on launch. They could then change the download url to be a modified Xcode or something else entirely allowing Xcodes to load malware onto the system without a user's knowledge.

I would have to look a lot deeper, but I wonder if a malformed file could also lead to privilege escalation via the helper tool.

@MattKiazyk I don't want to scare anyone or publish too many details publicly without a fix. How should we proceed? Am I wrong? Should I make a proof of concept for the downloading update?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions