Apple Vulnerabilities and Affected Products
Vulnerabilities associated with Xcode.
Products
Clear product- macOS3,219 vulnerabilities
- iOS and iPadOS1,660 vulnerabilities
- watchOS1,278 vulnerabilities
- tvOS1,206 vulnerabilities
- visionOS554 vulnerabilities
- iOS511 vulnerabilities
- Safari465 vulnerabilities
- iTunes for Windows192 vulnerabilities
- iPadOS185 vulnerabilities
- iCloud for Windows181 vulnerabilities
- iCloud for Windows (Legacy)75 vulnerabilities
- iphone_os64 vulnerabilities
- ipad_os53 vulnerabilities
- Multiple Products53 vulnerabilities
- Security Update - Catalina43 vulnerabilities
- Xcode43 vulnerabilities
- iCloud for Windows (Microsoft Store)22 vulnerabilities
- mac_os14 vulnerabilities
- iOS, iPadOS, and macOS11 vulnerabilities
- ios_and_ipados11 vulnerabilities
- MacOS X10 vulnerabilities
- AirPort Base Station Firmware Update7 vulnerabilities
- Apple Music for Android7 vulnerabilities
- itunes5 vulnerabilities
- GarageBand4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-28890MEDIUM | Generated title:Apple Xcode Out-of-Bounds Read Leading to Unexpected System TerminationAn out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination. CWE-125Mar 25, 2026 | CVSS5.5v3.1 | EPSS0.103% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28889MEDIUM | Generated title:Apple Xcode Permissions Issue Leading to Arbitrary File Read as RootA permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root. CWE-269Mar 25, 2026 | CVSS6.2v3.1 | EPSS0.112% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences. CWE-284Jan 16, 2026 | CVSS3.3v3.1 | EPSS0.141% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-43504MEDIUM | A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service. CWE-119Nov 4, 2025 | CVSS4.9v3.1 | EPSS0.349% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43505HIGH | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption. CWE-787Nov 4, 2025 | CVSS8.8v3.1 | EPSS0.268% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43375HIGH | The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. CWE-20Sep 15, 2025 | CVSS7.5v3.1 | EPSS0.318% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43263HIGH | The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox. CWE-284Sep 15, 2025 | CVSS7.1v3.1 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43371HIGH | This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox. CWE-284Sep 15, 2025 | CVSS8.2v3.1 | EPSS0.184% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-43370MEDIUM | A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process. CWE-120Sep 15, 2025 | CVSS4.0v3.1 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-30441MEDIUM | This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files. CWE-787Mar 31, 2025 | CVSS5.5v3.1 | EPSS0.221% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-24226MEDIUM | The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information. CWE-200Mar 31, 2025 | CVSS5.5v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44228HIGH | This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. CWE-276Oct 28, 2024 | CVSS7.5v3.1 | EPSS0.418% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44191MEDIUM | This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain unauthorized access to Bluetooth. Sep 16, 2024 | CVSS5.5v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-40862HIGH | A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer. CWE-200Sep 16, 2024 | CVSS7.5v3.1 | EPSS0.478% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-44162HIGH | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items. CWE-863Sep 16, 2024 | CVSS7.8v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-23298MEDIUM | A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks. Mar 15, 2024 | CVSS5.5v3.1 | EPSS0.525% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40435MEDIUM | This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. Sep 26, 2023 | CVSS5.5v3.1 | EPSS0.236% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-40391MEDIUM | The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory. Sep 26, 2023 | CVSS5.5v3.1 | EPSS0.307% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-32396HIGH | This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges. Sep 26, 2023 | CVSS7.8v3.1 | EPSS0.341% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-32920MEDIUM | The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information. Sep 6, 2023 | CVSS5.5v3.1 | EPSS0.181% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-27945MEDIUM | This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be able to collect system logs. CWE-125May 8, 2023 | CVSS6.3v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-27967HIGH | The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges. May 8, 2023 | CVSS8.6v3.1 | EPSS0.234% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-42797HIGH | An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges. CWE-74Feb 27, 2023 | CVSS7.8v3.1 | EPSS0.31% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-26747HIGH | This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges. May 26, 2022 | CVSS7.8v3.1 | EPSS0.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-22607HIGH | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution. CWE-125Mar 18, 2022 | CVSS7.8v3.1 | EPSS0.881% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |