Skip to content

☠️ Xcodes CLI password input can be eavesdroppable by, possibly, virtual private networks. #477

@ShikiSuen

Description

@ShikiSuen

I changed my Apple ID password 2 days ago.
Yesterday, I updated my system to macOS 27.0 Dev Beta 1, and XcodesApp fails to launch.
I then downloaded XcodeCLI trying to download Xcode 27.0 Dev Beta 1.

During the process, I was asked for Appke Credentials (both email and password).
I entered, then the doppelfactor throws me a verification code on my screen.
The CLI at this moment just failed instead of asking me to input the verification code.

The above is the only occasion I typed my Apple ID credentials at a non-Apple login form since that recent password change.

And then today I received an unauthorized login attempt from Amsterdam despite that I live outside of Europe.
I never tried European virtual private network nodes on mac.

P.S. I tried using Malwarebytes to scan my mac and found nothing suspecious.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions