Intel

AIKIDO-2025-10525

Iterable-iOS-SDK is vulnerable to Reliance on HTTP instead of HTTPS

Reliance on HTTP instead of HTTPS Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Aug 3, 2025

35

Low Risk

This Affects:

SWIFTIterable-iOS-SDK
6.0.0 - 6.5.12
Fixed in 6.5.13
Are you affected? Scan for Free

TL;DR

Affected versions of the package allow unsafe HTTP connections in the action runner logic, potentially exposing data to interception or tampering during transmission. This lack of enforced HTTPS can compromise the confidentiality and integrity of sensitive information exchanged between components, especially in untrusted network environments.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

Iterable-iOS-SDK is vulnerable to Reliance on HTTP instead of HTTPS in versions 6.0.0 - 6.5.12.

How to fix this

Upgrade the Iterable-iOS-SDK library to the patch version.