CVE-2025-31186
published 2026-01-16CVE-2025-31186: A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
PriorityP410low3.3CVSS 3.1
AVLACLPRNUIRSUCLINAN
EPSS
0.14%
3.9th percentile
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 16.3 | 16.3 |
| apple | xcode | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vqg4-vf9p-3qp9: A permissions issue was addressed with additional restrictions
ghsa_unreviewed·2026-01-16
CVE-2025-31186 [LOW] CWE-284 GHSA-vqg4-vf9p-3qp9: A permissions issue was addressed with additional restrictions
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Apple
CVE-2025-31186: Xcode 16.3
vendor_apple·2025-03-31·CVSS 3.3
CVE-2025-31186 [LOW] CVE-2025-31186: Xcode 16.3
Apple Security Update: About the security content of Xcode 16.3
Product: Xcode
Version: 16.3
CVE: CVE-2025-31186
Component: Playgrounds
Impact: An app may be able to bypass Privacy preferences
Description: A permissions issue was addressed with additional restrictions.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28889 [LOW] CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28889 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Simulator
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Comp
Wiz
CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28890 [LOW] CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28890 :
Xcode vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
otool
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-31186 [LOW] CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-31186 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Source : NVD
## 3.3
Score
Published January 16, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Playgrounds
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Compo
2026-01-16
Published