Security researchers have detected suspicious activity in the Apple Podcasts app, which might be used to deliver malicious content to users.
Sometimes, when I unlock my computer, the app starts up and displays one of these peculiar podcasts. Additionally, at least one podcast page in the app contains a link to a potentially malicious site. Another podcast, named in Arabic roughly translating to ‘Words of Life’, featured someone’s Gmail address. Sometimes the podcasts have actual sound, such as a religious sermon, while other times they are completely silent. Although the podcasts are often several years old, they are only just now being shown to me.
The author tested one of the podcasts and discovered a link in the description. This link attempts to direct listeners to a website that tries to execute a cross-site scripting (XSS) attack. This attack involves a hacker embedding their malicious code onto a seemingly normal website. The link is located in the ‘Show Website’ section of the podcast page. Clicking on it redirects to another site, followed by a pop-up with the message ‘XSS. Domain: domain name’.
Interestingly, a review of the Podcasts app exposed another person encountering the same issue, questioning how Apple permits XSS attacks.
The author consulted macOS security expert Patrick Wardle, who noted that the main issue with podcasts is that they can be launched directly via a link from any other site, whereas third-party apps would need confirmation to run.
I replicated similar behavior, though through a website: simply visiting a website can launch podcasts (and download a podcast selected by an attacker), requiring no user prompts or approvals, unlike other external applications on macOS (e.g., Zoom).
Of course, it’s essential to highlight that this is not an attack by itself. However, it creates a very efficient delivery mechanism if there is indeed a vulnerability within the Podcasts app. It remains unclear if these attempts have been successful, but the level of scrutiny indicates that attackers actively assess the Podcasts app as a potential target.
Wardle mentioned he has been trying to contact Apple for several months about this issue, but the company remains unresponsive. Perhaps they will react now that the information has reached the media.
On December 4, in China (as the model is not sold elsewhere), the official launch…
GreyNoise Labs has launched a free service called GreyNoise IP Check, which allows users to…
ASRock has expanded its lineup with two new mini-PCs in the DeskSlim series. The DeskSlim…
Company Fossibot has introduced the survivalist smartphone - the Fossibot F113. This new model is…
In recent days, the brightness of comet 3I/ATLAS has notably decreased by over one-third, even…
The Nuri rocket launched from Naro Space Center on November 27. This 47-meter rocket successfully…