RealVNC Becomes First and Only Remote Access Solution to Complete White Box Audit to Validate Security
VNC Connect by RealVNC, the remote access service used by hundreds of millions of people worldwide, was audited by Cure53, the Berlin, Germany-based IT security consultancy who have also audited other industry leading software such as Mozilla VPN, 1Password and Bitwarden. The comprehensive audit, which took 86 person days and included VNC Server and VNC Viewer on Linux, Windows and Mac, VNC Viewer for iOS and Android, the VNC Connect management portal and backend services, found 38 security-relevant discoveries, none of which were critical and only three were deemed high severity, and these were fixed immediately. The report states, in conclusion, that RealVNC places a strong focus on the security posture of all its components.
“As the technologists responsible for bringing remote access to the mass market, we are today setting new standards and expectations for security in the face of the challenges of the modern IT environment. IT buyers of remote access technologies should expect no less than independent and comprehensive third-party validation of vendor claims. This is especially true for remote access software where the stakes are high, and a mistake could be reputationally damaging or even existential. With Cure53’s report, buyers can be confident that choosing RealVNC as their remote access vendor will never be a regret,” said Adam Greenwood-Byrne, CEO of RealVNC.
A white box security audit is significantly more in-depth than the more common black box penetration test (which RealVNC also commissions by an external organization annually), as the auditors have access to all of the source code, binaries and API/protocol documentation. Of the 38 vulnerabilities found across the range of software and services tested, 32 have been properly addressed — with the fixes confirmed by Cure53 — while the other six were flagged as either false-alerts or works-as-intended and evaluated to be of lower risk.
“At RealVNC, we operate from the standpoint that no company should ever take a vendor’s word for it when they claim their software is secure, which is why we chose to complete a white box audit with a highly regarded security consultancy to prove it,” said Andrew Woodhouse, CIO of RealVNC.
The Cure53 team is highly motivated to find issues when completing white box penetration tests. The fact that no critical threats were found reinforces RealVNC’s focus on ensuring its customers remain safe from threats when using VNC Connect.
“Cure53 is happy to state that test preparation, test execution and also the fix verification, which is one of the most important parts of such an audit, went smoothly and professionally. It is clear that RealVNC has demonstrated a genuine interest in ensuring VNC Connect's security and is prepared and committed to maintaining the high standards we have observed,” said Dr.-Ing. Mario Heiderich, Founder of Cure53.
Headquartered in Cambridge, RealVNC's products for desktop, mobile and embedded platforms make it easy for users to access and operate devices remotely while enabling remote users to work with technicians to resolve problems easily.
“We’re not shying away from any of the issues the report found. We actively fixed issues as they came up and, as security is an ever changing landscape, we’ll continue to ensure the security of VNC Connect in future iterations of the service,” said Ben May, Head of Cyber Security at RealVNC.
To review Cure53's summary of the audit, click here, and to learn more about why RealVNC chose to conduct a Cure53 audit, click here.
ABOUT REALVNC
RealVNC’s secure remote access and management software is used by hundreds of millions of people worldwide. Their software helps organizations cut costs and improve the quality of supporting remote devices and applications, as well as enabling remote working. RealVNC is the original, UK-based, inventor of VNC remote access software and they support an unrivaled mix of desktop, mobile and embedded platforms.
ABOUT CURE53
Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits. Web application and mobile app developers speak many languages and so do we. From classic languages such as PHP, JavaScript, ActionScript, Java, Ruby, Python and Perl to more exotic candidates like web back-ends written in C++ and Delphi – we've seen them.
Since Cure53 was founded in 2007, we have performed hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools. We value manual and thorough tests, human interaction and communication and a short yet-to-the-point penetration test report without overhead or pie charts no one wants to see.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20220609005211/en/
Contact information
Lauren Meckstroth
lauren@theabbiagency.com
702.499.7388
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
GE HealthCare announces CE Mark for the Omni 128cm total body PET/CT system28.11.2025 13:00:00 EET | Press release
GE HealthCare today announced CE Mark for its next-generation Omni 128cm total body positron emission tomography / computed tomography (PET/CT) system,i a major milestone in its mission to advance precision care. Designed to advance cancer diagnosis, staging, therapeutic planning and treatment response monitoring, this innovative system represents a leap forward in molecular imaging capabilities and clinical efficiency. As global cancer rates continue to rise – projected to increase 77 percent by 2050ii – the need for advanced imaging solutions has never been greater. The growing prevalence of cancer and emergence of investigational immunotherapies and targeted treatments have accelerated the demand for whole-body PET/CT imaging. GE HealthCare’s new technology is built to meet this need, supporting theranostics and enabling clinicians to visualize, diagnose and monitor disease with impressive precision and speed. “Our commitment to precision health is rooted in innovation that also aim
King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah28.11.2025 11:53:00 EET | Press release
King Abdulaziz Foundation (Darah) held the first edition of the Forum on the “History of Hajj and the Two Holy Mosques”, convened as part of the program of the “Hajj Conference and Exhibition 2025” at the Super Dome Hall in Jeddah, in cooperation with the Ministry of Hajj and Umrah and the Guests of God Service Program, during the period from 9–12 November 2025. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20251128600368/en/ King Abdulaziz Foundation Organizes the First Edition of the Forum on the “History of Hajj and the Two Holy Mosques” in Jeddah (Photo: AETOSWire) The forum’s activities were inaugurated following the announcement by His Royal Highness Prince Faisal bin Salman bin Abdulaziz Al Saud, Special Advisor to the Custodian of the Two Holy Mosques and Chairman of the Board of Directors of the King Abdulaziz Foundation, who declared the launch of the forum during the opening ceremony of the “Hajj Conference and Exh
VSO Unveils VCP v1.0, a First-of-Its-Kind Cryptographic Audit Protocol to Restore Trust in AI-Driven Markets28.11.2025 07:30:00 EET | Press release
The VeritasChain Standards Organization (VSO), an independent international standards body, today announced the global release of VeritasChain Protocol (VCP) v1.0, an open cryptographic audit protocol designed to provide mathematically provable transparency for AI‑driven and algorithmic trading systems. VCP replaces mutable server logs with a tamper‑evident chain of cryptographic evidence, enabling regulators, brokers, exchanges and trading firms to move from trust‑based oversight to verification‑based supervision. Why This Matters Now The launch of VCP v1.0 comes at a pivotal moment for global market infrastructure: More than 80 proprietary trading firms collapsed between 2024 and 2025 amid regulatory scrutiny, opaque execution models and frozen payout disputes, leaving a trust gap between traders and platforms. Regulators worldwide are tightening expectations around algorithmic accountability — from U.S. enforcement actions against high‑risk retail FX schemes to the EU AI Act (high‑r
Stronghold’s SHx Token Lists on Uphold27.11.2025 17:00:00 EET | Press release
Stronghold announced that its SHx token is now available for retail users to trade on Uphold, the global multi-asset digital money platform known for its transparency, regulatory alignment, and seamless support for assets across both the Stellar and Ethereum networks. The listing marks a major milestone for SHx, expanding access for users and businesses who rely on Stronghold’s token for payments, settlements, and governance participation. "Uphold is one of the only platforms that provides seamless support for both Stellar and Ethereum-based tokens, making it a perfect fit for SHx as we grow our multi-chain ecosystem. This listing was championed by our community, and we’re thrilled to deliver on a request that so many SHx holders have been asking for." — Tammy Camp, CEO & Co-Founder, Stronghold SHx is Stronghold’s native utility token, powering interoperable payments, DeFi-based financing, and community governance. With over 215,000 global community members and thousands of merchants o
Wipro to Power Odido’s Digital Future Through AI-enabled End-to-End IT Modernization27.11.2025 15:22:00 EET | Press release
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, today announced a multi-year engagement with Odido Netherlands B.V.* to transform its IT landscape and enhance customer experience across their enterprise and consumer segments. By combining AI and deep consulting expertise, Wipro will help Odido improve customer engagement and satisfaction, improve productivity, and streamline operations to reduce costs. A key highlight of this multi-year engagement is the use of a self-funded model, where productivity-driven savings are reinvested to continuously fund new digital initiatives, ensuring that innovation remains both sustainable and scalable. As part of the engagement, Wipro will lead a full-scale modernization of Odido’s digital and enterprise technology landscape as well as drive IT simplification and automation. This transformation will be powered by Wipro’s WEGA and WINGS AI delivery platforms, part of Wipro Intelligen
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
