CVE Tools

Xcode

96 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Xcode, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Xcode CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Xcode CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-032
2025-040
2025-050
2025-060
2025-071
2025-080
2025-094
2025-100
2025-112
2025-120
2026-011
2026-020
2026-032
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 96 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical66%
  • High5052%
  • Medium3840%
  • Low22%

Latest CVEs

The 15 most recently published vulnerabilities affecting Xcode.

  1. CVE-2026-65393A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.5.5
  2. CVE-2026-28890An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.5.5
  3. CVE-2026-28889A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.6.2
  4. CVE-2025-31186A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.3.3
  5. CVE-2025-43504A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.4.9
  6. CVE-2025-43505An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.8.8
  7. CVE-2025-43375The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.5.5
  8. CVE-2025-43263The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.7.1
  9. CVE-2025-43371This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.8.2
  10. CVE-2025-43370A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.4.0
  11. CVE-2025-48384Git allows arbitrary code execution through broken config quoting8.0
  12. CVE-2025-30441This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.5.5
  13. CVE-2025-24226The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.5.5
  14. CVE-2024-44228This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.7.5
  15. CVE-2024-44191This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An ap...5.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store