« Back to list

Apple

Apple Xcode: vulnerabilities and CVEs

Apple Xcode has 96 published vulnerabilities, 6 of them in the last 12 months. 5 are rated critical and 2 are listed by CISA as actively exploited.

CVEs96
Last 12 months6
Critical5
Actively exploited2

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-48384High (8)4.2%⚠ Active exploitationJul 8, 2025
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing…
CVE-2021-44228Critical (10)100%⚠ Active exploitationDec 10, 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-65393Medium (5.5)0.16%—Sep 14, 2026
A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.
CVE-2026-28890Medium (5.5)0.14%—Mar 25, 2026
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
CVE-2026-28889Medium (6.2)0.15%—Mar 25, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
CVE-2025-31186Low (3.3)0.16%—Jan 16, 2026
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
CVE-2025-43505High (8.8)0.27%—Nov 4, 2025
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.
CVE-2025-43504Medium (4.9)0.35%—Nov 4, 2025
A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.
CVE-2025-43375Medium (5.5)0.34%—Sep 15, 2025
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.
CVE-2025-43371High (8.2)0.20%—Sep 15, 2025
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.
CVE-2025-43370Medium (4)0.34%—Sep 15, 2025
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.
CVE-2025-43263High (7.1)0.21%—Sep 15, 2025
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.
CVE-2025-48384High (8)4.2%⚠ Active exploitationJul 8, 2025
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing…
CVE-2025-30441Medium (5.5)0.23%—Mar 31, 2025
This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files.
CVE-2025-24226Medium (5.5)0.26%—Mar 31, 2025
The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.
CVE-2024-44228High (7.5)0.42%—Oct 28, 2024
This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.
CVE-2024-44191Medium (5.5)0.25%—Sep 17, 2024
This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. An app may gain…
CVE-2024-44162High (7.8)0.21%—Sep 17, 2024
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items.
CVE-2024-40862Medium (5.3)0.48%—Sep 17, 2024
A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer.
CVE-2024-23298Medium (5.5)0.52%—Mar 15, 2024
A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.
CVE-2023-40435Medium (5.5)0.27%—Sep 27, 2023
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
CVE-2023-40391Medium (5.5)0.32%—Sep 27, 2023
The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory.
CVE-2023-32396High (7.8)0.33%—Sep 27, 2023
This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges.
CVE-2022-32920Medium (5.5)0.21%—Sep 6, 2023
The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.
CVE-2023-27967High (8.6)0.23%—May 8, 2023
The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
CVE-2023-27945Medium (6.3)0.24%—May 8, 2023
This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be able to collect system logs.
CVE-2022-42797High (7.8)0.31%—Feb 27, 2023
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.
CVE-2022-39260High (8.8)3.3%—Oct 19, 2022
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull functionality via SSH. In versions prior to 2.30.6, 2.31.5,…
CVE-2022-39253Medium (5.5)1.3%—Oct 19, 2022
Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are subject to exposure of sensitive information to a malicious…
CVE-2022-29187High (7.8)0.45%—Jul 12, 2022
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could…
CVE-2022-26747High (7.8)0.64%—May 26, 2022
This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges.
CVE-2022-24765High (7.8)1.0%—Apr 12, 2022
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted…

📰 Related news

Other products by Apple