Home / Companies / Expo / Blog / Post Details
Content Deep Dive

Security notice for EAS Submit

Blog post from Expo

Post Details
Company
Date Published
Author
James Ide
Word Count
505
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

A remote code execution vulnerability in EAS Submit, linked to the Fastlane program, was reported by Xavier Bruni, prompting swift action to fix the issue. The vulnerability arose from Fastlane's failure to escape certain inputs before executing shell commands, potentially allowing unauthorized access to data across shared virtual machines (VMs) during iOS app submissions. Upon discovery, the iOS submission service was temporarily disabled, a hotfix was deployed, and additional input validations were added. To prevent future risks, EAS Submit transitioned to using individual ephemeral VMs for each submission job, ensuring enhanced isolation and security. Although no evidence of exploitation was found, users are advised to update their ASC API keys as a precaution.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.