Apple / Xcode
96 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-65393 | A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive… | MEDIUM | 5.5 | Sep 14, 2026 |
| CVE-2026-28890 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination. | MEDIUM | 5.5 | Mar 25, 2026 |
| CVE-2026-28889 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root. | MEDIUM | 6.2 | Mar 25, 2026 |
| CVE-2025-31186 | A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. | LOW | 3.3 | Jan 16, 2026 |
| CVE-2025-43504 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause… | MEDIUM | 4.9 | Nov 4, 2025 |
| CVE-2025-43505 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to… | HIGH | 8.8 | Nov 4, 2025 |
| CVE-2025-43375 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. | HIGH | 7.5 | Sep 15, 2025 |
| CVE-2025-43263 | The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox. | HIGH | 7.1 | Sep 15, 2025 |
| CVE-2025-43371 | This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. | HIGH | 8.2 | Sep 15, 2025 |
| CVE-2025-43370 | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. | MEDIUM | 4.0 | Sep 15, 2025 |
| CVE-2025-48384 KEV | Git allows arbitrary code execution through broken config quoting | HIGH | 8.1 | Jul 8, 2025 |
| CVE-2025-30441 | This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files. | MEDIUM | 5.5 | Mar 31, 2025 |
| CVE-2025-24226 | The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information. | MEDIUM | 5.5 | Mar 31, 2025 |
| CVE-2024-44228 | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user d… | HIGH | 7.5 | Oct 28, 2024 |
| CVE-2024-44191 | This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15,… | MEDIUM | 5.5 | Sep 16, 2024 |
| CVE-2024-40862 | A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of th… | HIGH | 7.5 | Sep 16, 2024 |
| CVE-2024-44162 | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items. | HIGH | 7.8 | Sep 16, 2024 |
| CVE-2024-23298 | A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks. | MEDIUM | 5.5 | Mar 15, 2024 |
| CVE-2023-40435 | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. | MEDIUM | 5.5 | Sep 26, 2023 |
| CVE-2023-40391 | The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to d… | MEDIUM | 5.5 | Sep 26, 2023 |
| CVE-2023-32396 | This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able… | HIGH | 7.8 | Sep 26, 2023 |
| CVE-2022-32920 | The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information. | MEDIUM | 5.5 | Sep 6, 2023 |
| CVE-2023-27967 | The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or wi… | HIGH | 8.6 | May 8, 2023 |
| CVE-2023-27945 | This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be abl… | MEDIUM | 6.3 | May 8, 2023 |
| CVE-2022-42797 | An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges. | HIGH | 7.8 | Feb 27, 2023 |
Showing 1 to 25 of 96 CVEs