Skip to content

Objective C

Objective C

Desteralization

Insecure Code:

id obj = [decoder decodeObjectForKey:@"myKey"];

if (![obj isKidOfClass:[MyClass class]]){
	//fail
}

Secure Code:

id obj = [decoder decodeObjectOfClass:[MyClass class] forKey:@"myKey"];