
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28890 is an out-of-bounds read vulnerability in the otool component of Apple Xcode that can allow a malicious app to cause unexpected system termination (denial of service). It affects all versions of Xcode prior to 26.4, running on macOS Tahoe 26.2 and later. The vulnerability was disclosed and patched on March 24, 2026, with credit to researcher Nathaniel Oh (@calysteon). It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and stems from improper bounds checking within the otool component of Xcode. An attacker can craft a malicious application that, when processed by the affected component, triggers a read operation beyond the allocated memory buffer, leading to unexpected system termination. Exploitation requires local access and user interaction (e.g., a user running the malicious app), and the attack scope is unchanged, meaning the impact is confined to the affected component (Apple Advisory).
Successful exploitation results in a denial-of-service condition — specifically, unexpected system termination of the affected application. There is no reported impact on confidentiality or integrity, as the vulnerability does not expose sensitive data or allow unauthorized modification of system state. The impact is limited to availability, and lateral movement or data exfiltration are not associated with this vulnerability (Apple Advisory).
Apple has addressed this vulnerability in Xcode 26.4, released March 24, 2026. Users should update Xcode to version 26.4 or later via the Mac App Store or Apple Developer downloads. As an interim measure, access to Xcode installations should be restricted to trusted users, and administrators should monitor for unexpected crashes or terminations in Xcode-related processes (Apple Advisory).
The CIS published an advisory noting multiple vulnerabilities in Apple products patched in this release cycle, including CVE-2026-28890. Community coverage was limited to automated vulnerability tracking platforms and brief social media posts, reflecting the low severity and limited exploitability of this issue. No significant researcher commentary or media coverage beyond routine patch reporting was identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."