Xcode
96 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for Xcode, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Xcode CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 1 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 2 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 4 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 2 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 96 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical6
- High50
- Medium38
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Xcode.
- CVE-2026-65393A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.5.5
- CVE-2026-28890An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.5.5
- CVE-2026-28889A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.6.2
- CVE-2025-31186A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.3.3
- CVE-2025-43504A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.4.9
- CVE-2025-43505An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.8.8
- CVE-2025-43375The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.5.5
- CVE-2025-43263The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.7.1
- CVE-2025-43371This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.8.2
- CVE-2025-43370A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.4.0
- CVE-2025-48384Git allows arbitrary code execution through broken config quoting8.0
- CVE-2025-30441This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.5.5
- CVE-2025-24226The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.5.5
- CVE-2024-44228This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.7.5
- CVE-2024-44191This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An ap...5.5
Product grouping is registry-driven, with AI assist and human review. How it works