CVE-2025-43263: High severity Apple Xcode vulnerability
Dev Tools. A path handling issue was addressed with improved validation.
Other sources
Dev Tools. The issue was addressed with improved checks.
— Apple
Git. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
IDE CoreML. The issue was addressed with improved checks.
— Apple
The issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to read and write files outside of its sandbox.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-43263?
CVE-2025-43263 is considered a moderate severity vulnerability affecting Apple's Xcode.
How do I fix CVE-2025-43263?
To fix CVE-2025-43263, update to the latest version of Apple Xcode beyond version 26.
Which versions of Xcode are affected by CVE-2025-43263?
CVE-2025-43263 affects Apple Xcode versions prior to 26.
What type of issue is represented by CVE-2025-43263?
CVE-2025-43263 represents a path handling issue that has been addressed with improved validation.
Is CVE-2025-43263 a vulnerability in open source software?
Yes, CVE-2025-43263 is a vulnerability found in open source code, specifically impacting Apple's software projects.