VulnerabilitiesHIGH

Xcode 26.4 - Critical Security Update Released

FDFull Disclosure+1 more
XcodeCVE-2026-28890CVE-2026-28889macOS TahoeApple
🎯

Basically, Apple fixed serious problems in Xcode that could crash apps or let others access files.

Quick Summary

Apple has rolled out Xcode 26.4 to fix serious vulnerabilities in macOS Tahoe. Developers should update immediately to prevent system crashes and unauthorized file access. Stay secure and keep your tools up to date!

The Flaw

Xcode 26.4, recently released by Apple, addresses critical security vulnerabilities affecting macOS Tahoe 26.2 and later. One of the significant issues is an out-of-bounds read, which could allow an app to cause unexpected system termination. This flaw is tracked as CVE-2026-28890. Additionally, there was a permissions issue that allowed apps to read arbitrary files as root, identified as CVE-2026-28889. Both vulnerabilities pose a serious risk to users, as they can lead to system instability and unauthorized access to sensitive data.

What's at Risk

The vulnerabilities primarily affect developers and users running Xcode on macOS Tahoe. If left unpatched, these flaws could lead to severe consequences, including data breaches and system crashes. The potential for unauthorized access to files means that sensitive information could be exposed, making it crucial for users to apply the update promptly. The impact is significant, as developers rely on Xcode for app development, and any disruption can hinder productivity.

Patch Status

Apple has made the Xcode 26.4 update available for download. Users can check their current version by selecting Xcode in the menu bar and clicking on 'About Xcode'. If the version is not updated to 26.4, it is essential to download the latest version from Apple's developer site. This update not only addresses the identified vulnerabilities but also includes improved bounds checking to prevent similar issues in the future.

Immediate Actions

To protect yourself and your projects, follow these steps:

  • Update Xcode: Download the latest version from Apple's developer site.
  • Verify the Update: Ensure that your version reflects Xcode 26.4.
  • Monitor for Further Updates: Keep an eye on Apple's Security Releases page for any additional advisories or updates related to Xcode and macOS.

By taking these actions, users can mitigate the risks associated with these vulnerabilities and ensure their development environment remains secure.

🔒 Pro insight: The presence of these vulnerabilities highlights the ongoing need for robust security practices in development environments, especially for widely-used tools like Xcode.

Original article from

FDFull Disclosure
Read Full Article

Also covered by

FUFull Disclosure

APPLE-SA-03-24-2026-10 Xcode 26.4

Read Article

Related Pings

HIGHVulnerabilities

Safari 26.4 - Critical Vulnerabilities Addressed

Apple has released Safari 26.4 to fix serious vulnerabilities in WebKit. This update is crucial for macOS users to protect against potential exploits. Make sure to update your software for enhanced security.

Full Disclosure·
HIGHVulnerabilities

libfuse io_uring Vulnerabilities - Critical Memory Flaws Found

Two critical memory safety vulnerabilities were discovered in libfuse's io_uring code path. These flaws could lead to crashes or arbitrary code execution. Immediate updates are advised.

Full Disclosure·
HIGHVulnerabilities

MailEnable Vulnerabilities - Multiple XSS Flaws Discovered

MailEnable has multiple reflected XSS vulnerabilities in versions 10.54 and earlier. Users are at risk of arbitrary script execution. Upgrade to version 10.55 to stay protected.

Full Disclosure·
HIGHVulnerabilities

macOS Tahoe 26.4 - Critical Security Updates Released

Apple has rolled out macOS Tahoe 26.4, fixing critical security vulnerabilities. Users could be at risk of data interception and unauthorized access. Update your system now to stay protected!

Full Disclosure·
HIGHVulnerabilities

Dovecot Security Advisory - Multiple Vulnerabilities Fixed

Dovecot has released a security advisory addressing multiple vulnerabilities. Users of Dovecot Pro and CE versions must update to prevent potential exploits. This advisory highlights critical flaws affecting user authentication and data integrity.

Full Disclosure·
HIGHVulnerabilities

Apple's tvOS 26.4 - Critical Security Updates Released

Apple has rolled out tvOS 26.4, fixing multiple serious vulnerabilities. Users of Apple TV HD and 4K need to update immediately to safeguard their devices against potential attacks. This update is crucial for maintaining device security.

Full Disclosure·