RealVNC Becomes First and Only Remote Access Solution to Complete White Box Audit to Validate Security
9.6.2022 16:00:00 EEST | Business Wire | Press release
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53, the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here, and to learn more about why RealVNC chose to conduct a Cure53 audit, click here.
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Contact information
Lauren Meckstroth
lauren@theabbiagency.com
702.499.7388
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Svante and Integrated Packaging Company Advance U.S. Biogenic CDR Project to Feasibility10.3.2026 15:57:00 EET | Press release
Svante Technologies Inc. (“Svante”) announced today that its bioenergy with carbon capture and storage (BECCS) project at a paper mill in the Southeast U.S. has progressed to the feasibility study phase. The project is being developed in partnership with an integrated sustainable packaging company, following an extensive screening and pre-feasibility study conducted across several of the partner’s mills. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260310319382/en/ During the feasibility study phase, the companies will complete further engineering and design activities, cost and schedule estimates, and risk assessments required to evaluate commercial viability ahead of a future engineering study leading to final investment decision (FID). Svante’s subsidiary, Svante Development Inc., is co-investing in this phase with the mill owner. The project is designed to capture and permanently store more than 500,000 tonnes per year
Forbes 40th Annual World’s Billionaires List10.3.2026 15:43:00 EET | Press release
Forbes releases its 40th-annual World’s Billionaireslist, the definitive ranking of the planet’s richest people. Wealth surged to unprecedented levels over the past year, with fortunes climbing at a record pace. This year’s list features 3,428 billionaires, the most since the list’s inception in 1987. The world’s wealthiest people are worth a record $20.1 trillion combined, up from $16.1 trillion in 2025. Elon Musktops the Billionaires list for the second year in a row and is the richest person ever recorded, worth an estimated $839 billion. His net worth skyrocketed by half of a trillion dollars from last year, thanks to a rise in the value of Tesla, and SpaceX which is aiming to go public in 2026. Musk is the first person ever recorded to reach the $800 billion mark, as he moves toward becoming the world’s first trillionaire. “It’s the year of the billionaire,” said Chase Peterson-Withorn, Forbes Senior Editor, Wealth. “The planet added more than one billionaire per day over the past
Andersen Global Expands African Presence with Addition of Bravura10.3.2026 15:30:00 EET | Press release
Andersen Global strengthens its presence in Africa through a Collaboration Agreement with Bravura, a leading independent tax and financial advisory firm based in South Africa and Namibia. Founded in 1999, Bravura provides tax and financial advisory solutions to listed and private companies, entrepreneurs, and high-net-worth families across the region. Bravura combines deep financial expertise with an entrepreneurial mindset to deliver tailored strategies that drive value. The firm’s multidisciplinary team provides advisory services in mergers and acquisitions, capital raising, corporate restructuring, and succession planning. Additionally, the firm offers tax and accounting strategy, international tax structuring, global mobility, and exchange control compliance solutions. “At Bravura, we’re driven to redefine standards and deliver bespoke, results-driven solutions that create lasting value for our clients,” said Ian Matthews, head of business development at Bravura. “Our collaboration
Adtran sets intra-data center benchmark with all-new ultra-low-power LiteWave800™ LPO module10.3.2026 15:00:00 EET | Press release
Adtran today launched LiteWave800™, an ultra‑low‑power 800Gbit/s DR8 linear pluggable optics (LPO) module engineered to help data centers address the power, latency, thermal and bandwidth demands of modern AI and machine-learning (ML) workloads. As GPU clusters grow and short-reach links scale across dense server racks, operators need 800Gbit/s optics that deliver higher capacity within strict power and cooling limits. LiteWave800™ answers this challenge with a fully re-engineered architecture that significantly reduces energy consumption. Operating at just 1pJ/bit and consuming only 0.8W, it establishes a new power class for 800Gbit/s optics, delivering far lower energy per bit than today’s first‑generation LPOs and mainstream DSP-based pluggable transceivers. Adtran will showcase LiteWave800™ at OFC 2026 in Los Angeles from March 17 to 19. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260310344607/en/ Adtran's LiteWave800
Verifone and Thales Unlock Seamless Global Connectivity for Payment Terminals10.3.2026 15:00:00 EET | Press release
At the core of this partnership is Thales’s leadership in eSIM management for large-scale connected devices, enabling remote connectivity provisioning and management, in line with the latest GSMA SGP.32 IoT specifications. These standards support secure and interoperable management of connectivity profiles, making it possible to deploy devices globally while maintaining full control over connectivity choices at local level. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260310957492/en/ Thales today announced a partnership with Verifone, a global leader in payment terminal solutions, to connect Verifone’s next-generation point-of-sale (POS) terminals using Thales eSIM technology. For Verifone, this approach transforms manufacturing and logistics. Devices can be produced in a single, standardized configuration, shipped anywhere in the world, and activated remotely once deployed. This streamlines supply chains, accelerates tim
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
