Apple Xcode vulnerabilities
115 known vulnerabilities affecting apple/xcode.
Total CVEs
115
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
2
Severity breakdown
CRITICAL10HIGH63MEDIUM38LOW4
Vulnerabilities
Page 6 of 6
CVE-2025-24226P4MEDIUMCVSS 5.5fixed in 16.32025-03-31
CVE-2025-24226 [MEDIUM] CWE-200 CVE-2025-24226: The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may
The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information.
nvdapple
CVE-2022-32920P4MEDIUMCVSS 5.5fixed in 14.0≥ unspecified, < 14.02023-09-06
CVE-2022-32920 [MEDIUM] CVE-2022-32920: The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may
The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.
nvdapple
CVE-2024-23298P4MEDIUMCVSS 5.5fixed in 15.32024-03-15
CVE-2024-23298 [MEDIUM] CVE-2024-23298: A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An ap
A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.
nvdapple
CVE-2015-7056P4MEDIUMCVSS 5.0≤ 7.1.12015-12-11
CVE-2015-7056 [MEDIUM] CWE-200 CVE-2015-7056: IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers
IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging the presence of a file matching an ignore pattern.
nvdapple
CVE-2025-43375P4MEDIUMCVSS 5.5fixed in 26.0fixed in 262025-09-15
CVE-2025-43375 [MEDIUM] CWE-20 CVE-2025-43375: The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly
The issue was addressed with improved checks. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.
nvdapple
CVE-2023-40435P4MEDIUMCVSS 5.5fixed in 15.0≥ unspecified, < 152023-09-27
CVE-2023-40435 [MEDIUM] CVE-2023-40435: This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may b
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.
nvdapple
CVE-2026-28890P4MEDIUMCVSS 5.5fixed in 26.42026-03-25
CVE-2026-28890 [MEDIUM] CWE-125 CVE-2026-28890: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
nvd
CVE-2006-1466P4MEDIUMCVSS 4.0≤ 2.22006-05-24
CVE-2006-1466 [MEDIUM] CVE-2006-1466: Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attacker
Xcode Tools before 2.3 for Mac OS X 10.4, when running the WebObjects plugin, allows remote attackers to access or modify WebObjects projects through a network service.
nvd
CVE-2008-2318P4MEDIUMCVSS 5.0v1.5v2.22008-07-14
CVE-2008-2318 [MEDIUM] CWE-200 CVE-2008-2318: The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session I
The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.
nvd
CVE-2015-7057P4MEDIUMCVSS 4.6≤ 7.1.12015-12-11
CVE-2015-7057 [MEDIUM] CVE-2015-7057: otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service
otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7049.
nvdapple
CVE-2015-7049P4MEDIUMCVSS 4.6≤ 7.1.12015-12-11
CVE-2015-7049 [MEDIUM] CWE-119 CVE-2015-7049: otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service
otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different vulnerability than CVE-2015-7057.
nvdapple
CVE-2025-43370P4MEDIUMCVSS 4.0fixed in 26.0fixed in 262025-09-15
CVE-2025-43370 [MEDIUM] CWE-120 CVE-2025-43370: A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Proce
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.
nvdapple
CVE-2019-1348P4LOWCVSS 3.3v11.22019-10-31
CVE-2019-1348 [LOW] CVE-2019-1348: Xcode 11.2
Apple Security Update: About the security content of Xcode 11.2
Product: Xcode
Version: 11.2
CVE: CVE-2019-1348
Component: Git
Impact: Git could allow a remote malicious user to bypass security restrictions, caused by a flaw in the --export-marks option of git fast-import
Description: An input validation issue was addressed.
apple
CVE-2015-5910P4LOWCVSS 3.3≤ 6.42015-09-18
CVE-2015-5910 [LOW] CWE-200 CVE-2015-5910: IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which a
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by sniffing the network.
nvdapple
CVE-2025-31186P4LOWCVSS 3.3fixed in 16.32026-01-16
CVE-2025-31186 [LOW] CWE-284 CVE-2025-31186: A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. A
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 16.3. An app may be able to bypass Privacy preferences.
nvdapple
← Previous6 / 6