The Apple Podcasts app can be used for hacking attacks. Hidden links have been discovered that can facilitate the infection of iOS and macOS devices.
Experts have noted "strange behavior" in the Apple Podcasts app. After taking a closer look, it turns out someone tried to use the program to attack Apple device users. Current information suggests that hackers are only testing various forms of attack, choosing podcast categories that attract less attention.
404 Media reports that suspicious behavior has been observed in Apple Podcasts over the past few months. The app was launching recordings, even those from several years ago, some of which were silent. The titles of the recordings contain hidden links to other websites, and four of them have been identified:
The real issue is how the app behaves on macOS. Apparently, Apple Podcasts can play a recording chosen by a hacker without the user even knowing, as mentioned by security specialist Patrick Wardle:
I replicated similar behavior, but through a web browser. Visiting the site is enough to launch Apple Podcasts and load the hacker's recording. Unlike other external apps, there is no request for permission to enable it.
Unfortunately, even after months of trying, Apple hasn't gotten back to us about a possible security issue with Apple Podcasts. Expert Joseph Cox, who published the reports, believes that, at least for now, the threat is not significant, and users of the program are aware of the risk, as shown by the ratings. Someone left a 1-star review on one of those recordings asking why Apple allows XSS attacks.
However, the situation may worsen over time. According to Wardle, hackers are just exploring the ground and the potential of Apple Podcasts for conducting other attacks. What's really worrying is that Apple hasn't said a word about this. Cox mentioned that they've ignored 5 emails on the topic, even though they usually reply to messages about other stuff.
0

Author: Zbigniew Woznicki
He began his adventure with journalism and writing on the Allegro website, where he published news related to games, technology, and social media. He soon appeared on Gamepressure and Filmomaniak, writing about news related to the film industry. Despite being a huge fan of various TV series, his heart belongs to games of all kinds. He isn't afraid of any genre, and the adventure with Tibia taught him that sky and music in games are completely unnecessary. Years ago, he shared his experiences, moderating the forum of mmorpg.org.pl. Loves to complain, but of course constructively and in moderation.
A firm NO to artificial intelligence. Clair Obscur: Expedition 33 devs don't hold back
Brainteaser answers in Dispatch. Let’s solve his riddles
Where to find Hollow Abode and Aureate Pavilion in Where Winds Meet. Navigation through Mistveil Forest has never been so easy
Answer to “Ice or roller” in Cookie Jam. Let’s find the solution
Which Mecha Man contains the bomb in Dispatch. Here’s how to complete Comically Yours