CVE-2025-43505
published 2025-11-04CVE-2025-43505: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.26%
18.2th percentile
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 26.1 | 26.1 |
| apple | xcode | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2025-43505: Xcode 26.1
vendor_apple·2025-11-03·CVSS 8.8
CVE-2025-43505 [HIGH] CVE-2025-43505: Xcode 26.1
Apple Security Update: About the security content of Xcode 26.1
Product: Xcode
Version: 26.1
CVE: CVE-2025-43505
Component: GNU
Impact: Processing a maliciously crafted file may lead to heap corruption
Description: An out-of-bounds write issue was addressed with improved input validation.
GHSA
GHSA-6wgr-2m33-vg69: An out-of-bounds write issue was addressed with improved input validation
ghsa_unreviewed·2025-11-04
CVE-2025-43505 [HIGH] CWE-787 GHSA-6wgr-2m33-vg69: An out-of-bounds write issue was addressed with improved input validation
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Xcode 26.1. Processing a maliciously crafted file may lead to heap corruption.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28889 [LOW] CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28889 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Simulator
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Comp
Wiz
CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28890 [LOW] CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28890 :
Xcode vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
otool
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-31186 [LOW] CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-31186 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Source : NVD
## 3.3
Score
Published January 16, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Playgrounds
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Compo
2025-11-04
Published