CVE-2026-28890
Xcode vulnerability analysis and mitigation

Overview

CVE-2026-28890 is an out-of-bounds read vulnerability in the otool component of Apple Xcode that can allow a malicious app to cause unexpected system termination (denial of service). It affects all versions of Xcode prior to 26.4, running on macOS Tahoe 26.2 and later. The vulnerability was disclosed and patched on March 24, 2026, with credit to researcher Nathaniel Oh (@calysteon). It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and stems from improper bounds checking within the otool component of Xcode. An attacker can craft a malicious application that, when processed by the affected component, triggers a read operation beyond the allocated memory buffer, leading to unexpected system termination. Exploitation requires local access and user interaction (e.g., a user running the malicious app), and the attack scope is unchanged, meaning the impact is confined to the affected component (Apple Advisory).

Impact

Successful exploitation results in a denial-of-service condition — specifically, unexpected system termination of the affected application. There is no reported impact on confidentiality or integrity, as the vulnerability does not expose sensitive data or allow unauthorized modification of system state. The impact is limited to availability, and lateral movement or data exfiltration are not associated with this vulnerability (Apple Advisory).

Mitigation and workarounds

Apple has addressed this vulnerability in Xcode 26.4, released March 24, 2026. Users should update Xcode to version 26.4 or later via the Mac App Store or Apple Developer downloads. As an interim measure, access to Xcode installations should be restricted to trusted users, and administrators should monitor for unexpected crashes or terminations in Xcode-related processes (Apple Advisory).

Community reactions

The CIS published an advisory noting multiple vulnerabilities in Apple products patched in this release cycle, including CVE-2026-28890. Community coverage was limited to automated vulnerability tracking platforms and brief social media posts, reflecting the low severity and limited exploitability of this issue. No significant researcher commentary or media coverage beyond routine patch reporting was identified.

Additional resources


SourceThis report was generated using AI

Related Xcode vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-43505HIGH8.8
  • Xcode logoXcode
  • GNU
NoYesNov 04, 2025
CVE-2026-28889MEDIUM6.2
  • Xcode logoXcode
  • Simulator
NoYesMar 25, 2026
CVE-2026-28890MEDIUM5.5
  • Xcode logoXcode
  • otool
NoYesMar 25, 2026
CVE-2025-43504MEDIUM4.9
  • Xcode logoXcode
  • lldb
NoYesNov 04, 2025
CVE-2025-31186LOW3.3
  • Xcode logoXcode
  • Playgrounds
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management