iOS¤ämacOS¸þ¤±¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó³«È¯¤ÇÍøÍѤµ¤ì¤ë¥é¥¤¥Ö¥é¥ê´ÉÍý¥Ä¡¼¥ë¤Î¡ÖCocoaPods¡×¤Ë¡¢²áµî10ǯ´Ö¤Ë¤ï¤¿¤Ã¤ÆÀȼå(¤¼¤¤¤¸¤ã¤¯)À­¤¬Â¸ºß¤·¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤ê¤Þ¤·¤¿¡£¤³¤ì¤Ë¤è¤ê¡¢300Ëü¸Ä¤â¤ÎiOS¤ª¤è¤ÓmacOS¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤¬¥µ¥×¥é¥¤¥Á¥§¡¼¥ó¹¶·â¤Î´íµ¡¤Ë¤µ¤é¤µ¤ì¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£

3 million iOS and macOS apps were exposed to potent supply-chain attacks | Ars Technica

https://arstechnica.com/security/2024/07/3-million-ios-and-macos-apps-were-exposed-to-potent-supply-chain-attacks/



Millions of iOS apps were exposed to CocoaPods security breach

https://9to5mac.com/2024/07/02/ios-apps-security-breach-cocoapods/

CocoaPods¤Î´ÉÍý¤Ë»ÈÍѤµ¤ì¤Æ¤¤¤ë¥È¥é¥ó¥¯¥µ¡¼¥Ð¡¼¤Ë¡¢ÀȼåÀ­¤¬Â¸ºß¤·¤Æ¤¤¤¿¤³¤È¤òÊó¹ð¤·¤¿¤Î¤Ï¡¢¥»¥­¥å¥ê¥Æ¥£´ë¶È¡¦E.V.A Information Security¤Î¸¦µæ¥°¥ë¡¼¥×¡£CocoaPods¤Ç¤Ï¸Ä¡¹¤Î¥³¡¼¥É¥Ñ¥Ã¥±¡¼¥¸¤ò»Ø¤¹¡Ö¥Ý¥Ã¥É¡×¤ËÊѹ¹¤ò²Ã¤¨¤ë¤È¡¢CocoaPods¤òÍøÍѤ·¤Æ¤¤¤ë¥¢¥×¥ê¤ÏÄ̾¥¢¥×¥ê¤Î¥¢¥Ã¥×¥Ç¡¼¥È¤òÄ̤¸¤Æ¤½¤ÎÊѹ¹¤ò¼«Æ°Åª¤Ë¼è¤êÆþ¤ì¤ë¤è¤¦À߷פµ¤ì¤Æ¤ª¤ê¡¢¥¨¥ó¥É¥æ¡¼¥¶¡¼¤Ë¤è¤ëÁàºî¤ÏɬÍפ¢¤ê¤Þ¤»¤ó¡£

E.V.A Information Security¤ÏCocoaPods¤Ç3¤Ä¤ÎÀȼåÀ­¤òȯ¸«¤·¤Æ¤ª¤ê¡¢¤³¤ì¤é¤Ï¸Ä¡¹¤Î¥Ý¥Ã¥É¤Î³«È¯¼Ô¤òǧ¾Ú¤¹¤ë¤¿¤á¤Ë»ÈÍѤµ¤ì¤ë¸¡¾Ú¥á¡¼¥ë¥á¥«¥Ë¥º¥à¤¬°ÂÁ´¤Ç¤Ï¤Ê¤«¤Ã¤¿¤³¤È¤¬¸¶°ø¤Ç¤¹¡£³«È¯¼Ô¤Ï¥Ý¥Ã¥É¤Ë´ØÏ¢ÉÕ¤±¤é¤ì¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ¹¤ë¤È¡¢¥È¥é¥ó¥¯¥µ¡¼¥Ð¡¼¤Ï¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ë¥ê¥ó¥¯¤òÁ÷¿®¤·¤Æ±þÅú¤·¤Þ¤¹¡£¥æ¡¼¥¶¡¼¤¬¤³¤Î¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤¹¤ë¤È¡¢¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¡£

CocoaPods¤«¤éÁ÷¿®¤µ¤ì¤ëÄ̾ï¤Îǧ¾Ú¥á¡¼¥ë



¤·¤«¤·¡¢¹¶·â¼Ô¤Ï¥È¥é¥ó¥¯¥µ¡¼¥Ð¡¼¤«¤é¤Î±þÅú¥á¡¼¥ë¤Ëµ¶Áõ¤·¤Æ¡¢¹¶·â¼Ô¤¬´ÉÍý¤¹¤ë¥µ¡¼¥Ð¡¼¤Ø¤Î¥ê¥ó¥¯¤òÁ÷¿®¤¹¤ë¤³¤È¤¬¤Ç¤­¤¿¤È¸¦µæ¼Ô¤Ï»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£¥µ¡¼¥Ð¡¼¤ÏHTTP¥ê¥¯¥¨¥¹¥È¤Ç»ØÄꤵ¤ì¤¿¥¿¡¼¥²¥Ã¥È¥Û¥¹¥È¤ò¼±Ê̤¹¤ë¤¿¤á¤ÎHTTP¥Ø¥Ã¥À¡¼¤È¤·¤Æ¡¢µ¶¤ÎXFH¤ò¼õ¤±Æþ¤ì¤¿¤½¤¦¤Ç¤¹¡£E.V.A Information Security¤Î¸¦µæ¼Ô¤Ï¡Öµ¶Â¤¤µ¤ì¤¿XFH¤ò»ÈÍѤ·¤ÆǤ°Õ¤ÎURL ¤ò¹½ÃۤǤ­¤¿¡×¤È»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£

¸¦µæ¼Ô¤¬µ¶Â¤¤·¤¿Ç§¾Ú¥á¡¼¥ë



¤Ê¤ª¡¢E.V.A Information Security¤¬È¯¸«¤·¤¿ÀȼåÀ­¤Ï°Ê²¼¤Î3¤Ä¡£

¡¦CVE-2024-38367

¡¦CVE-2024-38368

¡¦CVE-2024-38366

¤³¤Îµ¡Ç½¤ò°­ÍѤ·¤Æ¥¢¥×¥ê¤Ë°­°Õ¤Î¤¢¤ë¥³¡¼¥É¤òÁÞÆþ¤¹¤ë¤È¡¢¹¶·â¼Ô¤Ï¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¤ä°åÎŵ­Ï¿¤Ê¤É¤Î¥æ¡¼¥¶¡¼¤Î¸Ä¿Í¾ðÊó¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥é¥ó¥µ¥à¥¦¥§¥¢¹¶·â¤ò¹Ô¤Ã¤¿¤ê´ë¶È¥¹¥Ñ¥¤¤ò¹Ô¤Ã¤¿¤ê¤¹¤ë¤³¤È¤¬²Äǽ¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤·¤¿¡£E.V.A Information Security¤Î¸¦µæ¥Á¡¼¥à¤Ï¡Ö¹¶·â¼Ô¤Ï¥æ¡¼¥¶¡¼¤Î¸Ä¿Í¾ðÊó¤Ë¥¢¥¯¥»¥¹¤·¤Æ¡¢¥é¥ó¥µ¥à¥¦¥§¥¢¡¦º¾µ½¡¦¶¼Ç÷¡¦´ë¶È¥¹¥Ñ¥¤¤Ê¤É¡¢¹Í¤¨¤é¤ì¤ë¤Û¤Ü¤¢¤é¤æ¤ë°­°Õ¤Î¤¢¤ëÌÜŪ¤ËÍøÍѤǤ­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¤½¤Î²áÄø¤Ç¡¢´ë¶È¤Ï½ÅÂç¤ÊˡŪÀÕǤ¤äɾȽ¥ê¥¹¥¯¤Ë¤µ¤é¤µ¤ì¤ë²ÄǽÀ­¤¬¤¢¤ê¤Þ¤¹¡×¤È½Ò¤Ù¤Æ¤¤¤Þ¤¹¡£

CocoaPods¤Î¥á¥ó¥Æ¥Ê¡¼¤Ï2023ǯ10·î¤Ë¤³¤ì¤é¤ÎÀȼåÀ­¤ò¸ø³«¤·¡¢½¤Àµ¥Ñ¥Ã¥Á¤òÇÛÉÛ¤·¤Æ¤¤¤Þ¤¹¡£¥Ñ¥Ã¥ÁÇÛÉÛ»þ¡¢¥á¥ó¥Æ¥Ê¡¼¤Ï¡Ö¥µ¡¼¥Ð¡¼¾å¤ÇǤ°Õ¤Î¥·¥§¥ë¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤­¤ë¤È¤¤¤¦¤³¤È¤Ï¡¢¹¶·â¼Ô¤¬´Ä¶­ÊÑ¿ô¤òÆɤ߼è¤ëǽÎϤòÍ¿¤¨¡¢CocoaPods/Specs¥ê¥Ý¥¸¥È¥ê¤Ë½ñ¤­¹þ¤ß¡¢¥È¥é¥ó¥¯¥Ç¡¼¥¿¥Ù¡¼¥¹¤òÆɤ߼è¤ë¤³¤È¤¬¤Ç¤­¤ë¤³¤È¤ò°ÕÌ£¤·¤Þ¤¹¡×¡Ö¥æ¡¼¥¶¡¼¤òñÙ¤·¤Æ¥ê¥ó¥¯¤ò¥¯¥ê¥Ã¥¯¤µ¤»¡¢¥µ¡¼¥É¥Ñ¡¼¥Æ¥£¡¼¤Î¥µ¥¤¥È¤ËͶƳ¤¹¤ë¤³¤È¤Ç¡¢¥»¥Ã¥·¥ç¥ó¥­¡¼¤òÅð¤à¤³¤È¤¬¤Ç¤­¤Þ¤¹¡£¤³¤ì¤¬µ¯¤­¤¿¤«Èݤ«¤ÏÉÔÌÀ¤Ç¤¹¤¬¡¢°ÂÁ´ºö¤ò¤È¤ê¤¿¤¤¤È»×¤¤¤Þ¤¹¡×¤È¸ì¤ê¤Þ¤·¤¿¡£

CocoaPods¤Î¥á¥ó¥Æ¥Ê¡¼¤Ï¡ÖºÇ°­¤Î¥·¥Ê¥ê¥ª¤Ï¡¢¹¶·â¼Ô¤¬¤³¤Îµ»½Ñ¤òÍøÍѤ·¤Æ¥»¥Ã¥·¥ç¥ó¥­¡¼¤òÆþ¼ê¤·¡¢¥¢¥×¥ê³«È¯¼Ô¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤·¡¢Ç§¾Ú¤µ¤ì¤¿¥æ¡¼¥¶¡¼¤ò¥Ý¥Ã¥É¤ËÀܳ¤¹¤ë¤³¤È¡×¤È¸ì¤Ã¤Æ¤¤¤Þ¤¹¡£¤Ê¤ª¡¢E.V.A Information Security¤Î¸¦µæ¼Ô¤ÏCocoaPods³«È¯¼Ô¤Ë¤³¤ÎÀȼåÀ­¤òÈó¸ø³«¤ÇÄÌÃΤ·¤¿¸å¡¢ÅÐÏ¿¤µ¤ì¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÀ©¸æ¤Ç¤­¤Ê¤¤¸Â¤ê¡¢Ã¯¤â¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤Ç¤­¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë¡¢¤¹¤Ù¤Æ¤Î¥»¥Ã¥·¥ç¥ó¥­¡¼¤ò¾Ãµî¤·¤Þ¤·¤¿¡£



¤µ¤é¤Ë¡¢CocoaPods¤Ï¥á¥ó¥Æ¥Ê¡¼¤ËľÀÜÏ¢Íí¤¹¤ëɬÍפ¬¤¢¤ë¸Å¤¤¸ÉΩ¤·¤¿¥Ý¥Ã¥É¤ò²óÉü¤¹¤ë¤¿¤á¤Î¿·¤·¤¤¼ê½ç¤âÄɲᣥ¢¥×¥ê³«È¯¼Ô¤ä¥¢¥×¥ê¤ò»ÈÍѤ¹¤ë¥æ¡¼¥¶¡¼Â¦¤ÇɬÍפʥ¢¥¯¥·¥ç¥ó¤Ï¤¢¤ê¤Þ¤»¤ó¤¬¡¢E.V.A Information Security¤Î¸¦µæ¼Ô¤Ï¡Ö2023ǯ10·î°ÊÁ°¤ËCocoaPods¤ò»ÈÍѤ·¤Æ¤¤¤¿¥¢¥×¥ê³«È¯¼Ô¡×¤ËÂФ·¤Æ¡¢°Ê²¼¤Î¼ê½ç¤Ë½¾¤¦¤è¤¦¥¢¥É¥Ð¥¤¥¹¤·¤Æ¤¤¤Þ¤¹¡£

¡¦podfile.lock¥Õ¥¡¥¤¥ë¤ò¤¹¤Ù¤Æ¤ÎCocoaPods³«È¯¼Ô¤ÈƱ´ü¤µ¤»¤Æ¡¢Á´°÷¤¬Æ±¤¸¥Ð¡¼¥¸¥ç¥ó¤Î¥Ñ¥Ã¥±¡¼¥¸¤ò»ÈÍѤ·¤Æ¤¤¤ë¤³¤È¤ò³Îǧ¤·¤Þ¤¹¡£¤³¤ì¤Ë¤è¤ê¡¢ÀøºßŪ¤ËÍ­³²¤Ê¿·¤·¤¤¹¹¿·¤¬¥³¥ß¥Ã¥È¤µ¤ì¤¿¤È¤­¤Ë¡¢³«È¯¼Ô¤¬¼«Æ°Åª¤Ë¹¹¿·¤¹¤ë¤³¤È¤¬¤Ê¤¯¤Ê¤ê¤Þ¤¹¡£

¡¦¼ÒÆâ¤Ç³«È¯¤µ¤ì¡¢ÂçÎÌÇÛÉÛÍѤËCocoaPods¤Ç¤Î¤ß¥Û¥¹¥È¤µ¤ì¤Æ¤¤¤ë¥Ý¥Ã¥É¤ò»ÈÍѤ·¤Æ¤¤¤ë¾ì¹ç¡¢³«È¯¼Ô¤ÏCocoaPods¥È¥é¥ó¥¯¥µ¡¼¥Ð¡¼¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤¿¤â¤Î¤ËÂФ·¤ÆCRC(¥Á¥§¥Ã¥¯¥µ¥à)¸¡¾Ú¤ò¼Â¹Ô¤·¡¢¼ÒÆâ¤Ç³«È¯¤µ¤ì¤¿¤â¤Î¤ÈƱ¤¸¤Ç¤¢¤ë¤³¤È¤ò³Îǧ¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£

¡¦¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ç»ÈÍѤµ¤ì¤ë¥µ¡¼¥É¥Ñ¡¼¥Æ¥£¡¼¥³¡¼¥É¤ÎÅ°ÄìŪ¤Ê¥»¥­¥å¥ê¥Æ¥£¥ì¥Ó¥å¡¼¤ò¼ÂÁõ¤·¤Þ¤¹¡£

¡¦CocoaPods¤Î°Í¸´Ø·¸¤ò³Îǧ¤·¡¢¸ÉΩ¤·¤¿¥Ý¥Ã¥É¤ò»ÈÍѤ·¤Æ¤¤¤Ê¤¤¤³¤È¤ò³Îǧ¤·¤Þ¤¹¡£

¡¦ÀѶËŪ¤ËÊݼ餵¤ì¡¢½êÍ­¸¢¤¬ÌÀ³Î¤Ê¥µ¡¼¥É¥Ñ¡¼¥Æ¥£¡¼¤Î°Í¸´Ø·¸¤ò»ÈÍѤ¹¤ë¤è¤¦¤Ë¤·¤Æ¤¯¤À¤µ¤¤¡£

¡¦Äê´üŪ¤Ë¥»¥­¥å¥ê¥Æ¥£¥³¡¼¥É¥¹¥­¥ã¥ó¤ò¼Â¹Ô¤·¤Æ¡¢¤¹¤Ù¤Æ¤Î³°Éô¥é¥¤¥Ö¥é¥ê(ÆäËCocoaPods)¾å¤Î°­°Õ¤Î¤¢¤ë¥³¡¼¥É¤ò¸¡½Ð¤·¤Þ¤¹¡£

¡¦Èó¾ï¤Ë¹­¤¯»ÈÍѤµ¤ì¤Æ¤¤¤ë°Í¸´Ø·¸¤Ï¡¢ÀøºßŪ¤Ê¹¶·â¼Ô¤Ë¤È¤Ã¤Æ¤è¤êÌ¥ÎÏŪ¤Ê¥¿¡¼¥²¥Ã¥È¤È¤Ê¤ë²ÄǽÀ­¤¬¤¢¤ë¤¿¤á¡¢Ãí°Õ¤·¤Æ¤¯¤À¤µ¤¤¡£

¤Ê¤ª¡¢E.V.A Information Security¤Î¸¦µæ¼Ô¤Ï¡ÖÀøºßŪ¤Ê¥³¡¼¥ÉÊѹ¹¤Ï¡¢iPhone¡¢Mac¡¢Apple TV¡¢Apple Watch¥Ç¥Ð¥¤¥¹¤Ê¤ÉÀ¤³¦Ãæ¤Î²¿É´ËüÂæ¤â¤ÎApple¥Ç¥Ð¥¤¥¹¤Ë±Æ¶Á¤òÍ¿¤¨¤ë²ÄǽÀ­¤¬¤¢¤ê¤Þ¤¹¡×¤È¸ÀµÚ¤·¤Æ¤¤¤Þ¤¹¡£