FirebasePerformance is vulnerable to Use after free
36
Low Risk
Affected versions of this package are vulnerable to a Use After Free issue in the didCompleteRequestWithResponse:error: method, where response.MIMEType is accessed from a deallocated NSURLResponse object. This can cause an EXC_BAD_ACCESS crash under certain network or SDK conditions due to premature deallocation and thread-safety issues. The fix ensures the MIME type is safely copied before use to prevent accessing freed memory.
You are affected if you are using a version that falls within the vulnerable range.
FirebasePerformance is vulnerable to Use after free in versions 7.4.0 - 12.3.0.
Upgrade the FirebasePerformance library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant