RealVNC Becomes First and Only Remote Access Solution to Complete White Box Audit to Validate Security
9.6.2022 16:00:00 EEST | Business Wire | Press release
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53, the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here, and to learn more about why RealVNC chose to conduct a Cure53 audit, click here.
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Contact information
Lauren Meckstroth
lauren@theabbiagency.com
702.499.7388
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Forrester Announces The Agenda For Its 2026 CX Events To Help Address The Challenges AI Can’t Handle Alone2.3.2026 16:30:00 EET | Press release
Forrester (Nasdaq: FORR) today announced the agenda for its global customer experience (CX) event series: CX Summit EMEA, being held in Amsterdam, June 8–10, 2026; CX Forum East, being held in New York City, June 16–17, 2026; and CX Forum West, being held in San Francisco, June 29–30, 2026. Today, CX, marketing, and digital business leaders are under mounting pressure to leverage AI to architect smarter end-to-end customer journeys, automate service, operationalize AI agents, and deliver true personalization at scale — all while consumer trust is at an all-time low. While AI is promising to raise the bar for speed and efficiency, beneath every customer experience is a foundation that AI alone can’t build. To forge trust, organizations need to embed human creativity, context, customer identity, and quality data into every customer interaction. This year’s theme, “Build The Experience AI Can’t,” will empower leaders to shift from doing more with AI to creating better experiences powered
Incode First to Achieve iBeta’s Highest Level of Independent Identity Security Testing on Both iOS and Android With 0% Error Rate2.3.2026 16:00:00 EET | Press release
Incode Technologies, Inc., the global leader in identity security and fraud prevention, today announced that iBeta PAD testing confirmed Incode’s face liveness technology achieves Level 3 Presentation Attack Detection (PAD) conformance under ISO/IEC 30107-3. "We are the first company to independently achieve iBeta Level 3 conformance on both iOS and Android – with zero errors and without adding friction to users," said Ricardo Amper, Founder & CEO at Incode. "That combination matters. It proves we can meet the highest bar for liveness assurance while keeping onboarding fast and easy, even in regulated and high-risk environments." Face liveness technology is used in digital onboarding and authentication to confirm a real, live person is present during a selfie capture – not a printed photo, video replay, mask, or other spoofing attempt. It enables organizations to defend remote identity verification flows against account takeovers, synthetic identity fraud, and impersonation scams. Inco
Safe Software Expands its FME Platform with MCP2.3.2026 16:00:00 EET | Press release
Today, Safe Software (Safe), the creator of FME, the only All-Data, Any-AI enterprise integration platform with true support for spatial data, announced that Model Context Protocol (MCP) capabilities are coming soon to its FME Platform. This update expands what organizations can do with their existing data and workflows. As organizations move AI from experimentation to production they face growing challenges around context management, interoperability, and security. MCP provides a standardized way for AI, agents and other systems to interact with external systems, such as databases, internal tools, and APIs, without hard-coding integrations. “Adding MCP to the FME Platform is an important step in our All-Data, Any-AI mission,” said Don Murray, CEO of Safe Software. “With MCP, our customers can adopt new AI models without rebuilding integrations. By extending FME Flow with MCP Server capabilities, we’re giving organizations a future-proof way to let AI securely work with the systems the
Smartly Announces Amazon DSP Integration to Extend Intelligent Creative and Campaign Management to Connected TV2.3.2026 15:59:00 EET | Press release
Smartly announced today an integration with Amazon DSP that enables advertisers to extend their Smartly video campaigns to Amazon's premium CTV inventory, including Prime Video and Fire TV, and third-party publisher inventory. The new integration addresses growing market demand as CTV investment accelerates, with nearly 70% of marketers1 planning to increase streaming budgets over the next year while seeking more personalization, agility, and measurable outcomes from their campaigns. The Smartly integration with Amazon DSP is available globally, with additional features rolling out later in 2026. The integration brings streaming TV activation into advertisers' existing workflows in Smartly through three core capabilities. Smartly enables AI-powered creative optimization and personalization from social channels to streaming. The new capability eliminates the creative production bottlenecks that prevent many advertisers from activating CTV campaigns. Advertisers can then create, manage,
Lone Star Funds Completes Sale of SPX FLOW to ITT Inc.2.3.2026 15:50:00 EET | Press release
Lone Star Funds (“Lone Star”) today announced that an affiliate of Lone Star Fund XI, L.P. has successfully completed the sale of SPX FLOW, Inc. (“SPX FLOW”), a leading provider of highly engineered equipment and process technologies for attractive end markets including industrial, health and nutrition, to ITT Inc. (NYSE: ITT) for $4.775 billion in cash and shares of ITT common stock. SPX FLOW focuses on process technologies delivering mixing, blending, fluid handling, separation, thermal heat transfer and other solutions integral to industrial, health and nutrition markets. The company has operations in more than 25 countries and sales in more than 140 countries. Since acquiring SPX FLOW, Lone Star has worked alongside the company’s leaders to further develop its operations and product capabilities. Together, Lone Star and SPX FLOW improved the company’s commercial organization and executed growth initiatives that have positioned it for long-term success. “We are pleased to reach this
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
