CVE-2025-43504
published 2025-11-04CVE-2025-43504: A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause…
PriorityP423medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
0.34%
26.6th percentile
A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 26.1 | 26.1 |
| apple | xcode | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43504: Xcode 26.1
vendor_apple·2025-11-03·CVSS 4.9
CVE-2025-43504 [MEDIUM] CVE-2025-43504: Xcode 26.1
Apple Security Update: About the security content of Xcode 26.1
Product: Xcode
Version: 26.1
CVE: CVE-2025-43504
Component: GNU
Impact: Processing a maliciously crafted file may lead to heap corruption
Description: An out-of-bounds write issue was addressed with improved input validation.
GHSA
GHSA-p867-9m9g-6jj4: A buffer overflow was addressed with improved bounds checking
ghsa_unreviewed·2025-11-04
CVE-2025-43504 [MEDIUM] CWE-119 GHSA-p867-9m9g-6jj4: A buffer overflow was addressed with improved bounds checking
A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28889 [LOW] CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28889 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Simulator
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Comp
Wiz
CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28890 [LOW] CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28890 :
Xcode vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
otool
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-31186 [LOW] CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-31186 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Source : NVD
## 3.3
Score
Published January 16, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Playgrounds
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Compo
2025-11-04
Published