RealVNC Becomes First and Only Remote Access Solution to Complete White Box Audit to Validate Security
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53, the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here, and to learn more about why RealVNC chose to conduct a Cure53 audit, click here.
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Contact information
Lauren Meckstroth
lauren@theabbiagency.com
702.499.7388
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Geoswift Launches Visa Direct to Enhance Cross-Border Payment Offers in Over 30 Countries30.4.2025 04:00:00 EEST | Press release
Geoswift announced today the integration of Visa Direct with Geoswift's cross-border payments platform. Visa Direct facilitates payouts to more than 140 countries and territories. The integration will enable payouts in 32 countries and territories, across 13 currencies, covering major markets in Asia Pacific, North America, Europe and Middle East, with plans for more in the future. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250423288249/en/ Bryan Ma, SVP, Head of Geoswift Global Payments, and Swapnil Mhasde, Head of Visa Direct Commercialization and Solutions, Asia Pacific, celebrating the launch in Singapore. Geoswift is a leading provider of cross-border payment services and solutions globally. With over two decades of innovation, it has become a trusted name in B2B, education, eCommerce, remittance, and travel payment use cases. Raymond Qu, Group CEO of Geoswift, stated, "At Geoswift, our vision has always been to del
Logitech Announces Q4 and Full Fiscal Year 2025 Results29.4.2025 23:03:00 EEST | Press release
SIX Swiss Exchange Ad hoc announcement pursuant to Art. 53 LR — Logitech International (SIX: LOGN) (Nasdaq: LOGI) today announced financial results for the fourth quarter and full Fiscal Year 2025 ended March 31, 2025. For Fiscal Year 2025: Sales were $4.55 billion, up 6 percent in US dollars and 7 percent in constant currency, compared to the prior year. GAAP operating income was $655 million, up 11 percent compared to the prior year. Non-GAAP operating income was $775 million, up 11 percent compared to the prior year. GAAP earnings per share (EPS) was $4.13, up 7 percent compared to the prior year. Non-GAAP EPS was $4.84, up 14 percent compared to the prior year. Cash flow from operations was $843 million. The year-ending cash balance was $1.5 billion. The Company returned $797 million of cash to shareholders through its annual dividend payment and share repurchases. For Q4 Fiscal Year 2025: Sales were $1.01 billion, flat in US dollars and up 2 percent in constant currency, compared
U.S. Patent and Trademark Office Invalidates Pharmacyclics Patent Asserted Against BeiGene29.4.2025 22:32:00 EEST | Press release
BeiGene, Ltd. (NASDAQ: ONC; HKEX: 06160; SSE: 688235), a global oncology company that intends to change its name to BeOne Medicines Ltd., today announced that the U.S. Patent and Trademark Office (USPTO) rendered a Final Written Decision invalidating all claims of Pharmacyclics LLC’s (Pharmacyclics) U.S. Patent No. 11,672,803 (the ‘803 patent) that were challenged by BeiGene in a post-grant review (PGR) proceeding. On November 1, 2023, BeiGene filed a PGR petition with the USPTO challenging the validity of certain claims of the ‘803 patent, in response to a patent infringement lawsuit Pharmacyclics brought against BeiGene concerning BRUKINSA® (zanubrutinib). On May 1, 2024, the USPTO granted BeiGene’s petition to institute the PGR. The USPTO’s Final Written Decision is appealable by Pharmacyclics. Commenting on the ruling, BeiGene General Counsel Chan Lee said: “We are pleased that the USPTO invalidated all challenged claims of the ‘803 patent. Today’s decision reinforces our belief th
One out of Three Secure Civil IDs Delivered Each Year Is Powered by Thales29.4.2025 17:50:00 EEST | Press release
Each year, Thales powers one in three smart civil IDs (official electronic documents) issued worldwide, highlighting the company’s key role in shaping the future of identities and helping governments and citizens transition smoothly to digital. With its Civil Identity Suite, Thalesenables the issuance and management of both physical and digital identities, as well as all means of enrolling citizens and enabling seamless ID verification for access to services, both in-person and online. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250429687137/en/ Thales Civil Id Suite (Photo: Thales Shutterstock) Thales, a global leader in advanced technologies and #1 global leader in ID documents, has recently earned the new title of #1 provider of Digital ID solutions as recognized by Juniper Research (2024). With unmatched experience and scale, Thales empowers governments to modernise their identity systems, ensuring they meet the deman
Andersen Global Enhances European Valuation Capabilities through Collaboration with Value & Risk Valuation Services29.4.2025 16:30:00 EEST | Press release
Andersen Global continues to strengthen its valuation capabilities through a Collaboration Agreement with Value & Risk Valuation Services, a prominent European valuation firm headquartered in Germany with offices in Luxembourg and Austria. Founded in 1996, Value & Risk Valuation Services is a management-owned firm specializing in the valuation of financial assets across diverse asset classes and varying complexities. The firm also provides complementary services, including independent price verification (IPV), risk analysis, and transaction cost analysis. Since 2009, the company has been led by Gil Bender, who is dedicated to delivering high-quality, client-centric valuation solutions. As one of the few European providers offering external valuation services in compliance with the European Alternative Investment Fund Managers Directive (AIFMD), Value & Risk upholds the highest industry standards for regulatory compliance and service excellence. “Since our inception, we have focused on
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom