Description
Concatenating user input into a Realm filter expression can let an attacker alter the predicate, retrieve unauthorized data, or bypass filter conditions.
Potential impact
- Local database filter bypass
- Access to Realm objects outside the user's permissions
- Sensitive data exposure
Remediation
- Keep the Realm filter string static.
- Pass user values separately through
%@placeholders. - Select field names and sort criteria only from an allow-list.
Examples
Before
swift
let matches = users.filter("name == '\(username)'")
After
swift
let matches = users.filter("name == %@", username)
Explanation:
- Before: User input becomes part of the Realm expression.
- After: User values remain separate from the expression's structure.