[iOS IMA SDK] Insecure Usage of NSClassFromString

9 views
Skip to first unread message

Weili Liu

unread,
Aug 14, 2025, 8:03:50 AMAug 14
to Interactive Media Ads SDK
Hi Team,

Our security scan flagged the Google IMA iOS SDK (version 3.23.0) due to the presence of NSClassFromString calls in the binary.

Since NSClassFromString is inherently insecure, can you reimplement the functionality in safe manner? In the meantime, can you explain how is this method being currently used and if you have additional mitigations in place to alleviate security risks

We need this information to address concerns raised during our security review.

Thanks!
Reply all
Reply to author
Forward
0 new messages