CVE-2026-28889
published 2026-03-25CVE-2026-28889: A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
PriorityP430medium6.2CVSS 3.1
AVLACLPRNUINSUCHINAN
EPSS
0.11%
1.6th percentile
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 26.4 | 26.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28889 [LOW] CVE-2026-28889 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28889 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Source : NVD
## 6.2
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.2
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Simulator
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Comp
Wiz
CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2026-28890 [LOW] CVE-2026-28890 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28890 :
Xcode vulnerability analysis and mitigation
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Source : NVD
## 5.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
otool
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Wiz
CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-31186 [LOW] CVE-2025-31186 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-31186 :
Xcode vulnerability analysis and mitigation
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
Source : NVD
## 3.3
Score
Published January 16, 2026
Severity LOW
CNA Score 3.3
Affected Technologies
Xcode
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Playgrounds
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Xcode vulnerabilities:
CVE ID
Severity
Score
Technologies
Compo
2026-03-25
Published