Swift NSPredicate Injection

Swift NSPredicate injection

Description

Building the format string for NSPredicate(format:) from external input lets an attacker alter the expression, potentially retrieving unintended objects or bypassing filters.

Potential impact

  • Access to objects outside the user's permissions
  • Filter bypass
  • Application logic bypass or data exposure

Remediation

  1. Keep the format string for NSPredicate(format:) static.
  2. Pass values separately through %@ placeholders.
  3. Select dynamic field names and operators from an allow-list.

Examples

Before

swift
let predicate = NSPredicate(format: "name == '\(username)'")

After

swift
let predicate = NSPredicate(format: "name == %@", username)

Explanation:

  • Before: User input is interpreted as predicate syntax.
  • After: User input is supplied only as a value argument.

References