Apple Xcode Vulnerabilities Allow Information Disclosure, Denial of Service
Summary
CERT-Bund has issued a security advisory for Apple Xcode, detailing multiple vulnerabilities that could allow remote attackers to disclose information or cause a denial of service. The advisory notes a CVSS Base Score of 5.5 (medium) and affects versions prior to 26.4 on MacOS X.
What changed
CERT-Bund has published a security advisory (WID-SEC-2026-0859) concerning multiple vulnerabilities in Apple Xcode, specifically affecting versions prior to 26.4 on MacOS X. These vulnerabilities, rated with a CVSS Base Score of 5.5 (medium), can be exploited by remote, anonymous, or local attackers to achieve information disclosure and denial of service conditions.
Organizations utilizing Apple Xcode for software development should immediately review their installed versions. Mitigation is available, and affected parties are advised to update to a patched version or implement recommended security controls to prevent exploitation. Failure to address these vulnerabilities could lead to unauthorized access to sensitive information or disruption of development services.
What to do next
- Review installed versions of Apple Xcode for versions prior to 26.4.
- Implement available mitigations or update to a patched version of Xcode.
- Assess potential impact of information disclosure and denial of service vulnerabilities on development operations.
Source document (simplified)
[WID-SEC-2026-0859] Apple Xcode: Mehrere Schwachstellen CVSS Base Score 5.5 (mittel) CVSS Temporal Score 4.8 (mittel) Remoteangriff nein Datum 24.03.2026 Stand 25.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- MacOS X
Produktbeschreibung
Xcode ist eine integrierte Entwicklungsumgebung von Apple, mit der man Programme für Mac OS X und iOS schreiben kann. Das Programm ist nur für Mac OS X verfügbar.
Produkte
24.03.2026
- Apple Xcode <26.4
Angriff
Angriff
Ein entfernter, anonymer oder lokaler Angreifer kann mehrere Schwachstellen in Apple Xcode ausnutzen, um Informationen offenzulegen und um einen Denial of Service Zustand herbeizuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.