Description
Building the format string for NSPredicate(format:) from external input lets an attacker alter the expression, potentially retrieving unintended objects or bypassing filters.
Potential impact
- Access to objects outside the user's permissions
- Filter bypass
- Application logic bypass or data exposure
Remediation
- Keep the format string for
NSPredicate(format:)static. - Pass values separately through
%@placeholders. - Select dynamic field names and operators from an allow-list.
Examples
Before
swift
let predicate = NSPredicate(format: "name == '\(username)'")
After
swift
let predicate = NSPredicate(format: "name == %@", username)
Explanation:
- Before: User input is interpreted as predicate syntax.
- After: User input is supplied only as a value argument.