Skip to main content

Vendor/product archive

apple / xcode CVEs

Beta · best-effort

95 CVEs tagged to apple / xcode6 Critical, 50 High, 37 Medium, 2 Low, 0 Unrated.

CVE-2026-28890

Published Mar 25, 2026

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-28889

Published Mar 25, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31186

Published Jan 16, 2026

A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43505

Published Nov 4, 2025

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-43504

Published Nov 4, 2025

A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43375

Published Sep 15, 2025

The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43371

Published Sep 15, 2025

This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-43370

Published Sep 15, 2025

A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43263

Published Sep 15, 2025

The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48384

Published Jul 8, 2025

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading…

CVSS 8.0 · High
evidence mentions
4
Buzz score
49.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-30441

Published Mar 31, 2025

This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24226

Published Mar 31, 2025

The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-44228

Published Oct 28, 2024

This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-44162

Published Sep 17, 2024

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40862

Published Sep 17, 2024

A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23298

Published Mar 15, 2024

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40435

Published Sep 27, 2023

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32920

Published Sep 6, 2023

The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27967

Published May 8, 2023

The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27945

Published May 8, 2023

This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be able to collect system…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-42797

Published Feb 27, 2023

An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 95 CVEsPage 1 of 4