Out-of-Bounds Read Vulnerability in Apple Xcode
CVE-2026-28890

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-28890?

An out-of-bounds read vulnerability in Apple Xcode was identified, which could allow an application to perform unexpected actions leading to system instability or termination. This issue has been mitigated through enhanced bounds checking measures in the updated Xcode 26.4 release, emphasizing the importance of applying the latest security updates to maintain system integrity and performance.

Affected Version(s)

Xcode 0 < 26.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.