CVE-2025-43371: High severity Apple Xcode vulnerability
Dev Tools. A path handling issue was addressed with improved validation.
Other sources
Dev Tools. The issue was addressed with improved checks.
— Apple
Git. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
IDE CoreML. The issue was addressed with improved checks.
— Apple
This issue was addressed with improved checks. This issue is fixed in Xcode 26. An app may be able to break out of its sandbox.
— MITRE
Xcode. This issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-43371?
CVE-2025-43371 has been classified with a severity that indicates a significant risk to users of affected Apple Xcode versions.
How do I fix CVE-2025-43371?
To fix CVE-2025-43371, users should update to the latest version of Apple Xcode that is compatible beyond version 26.
Which versions of Xcode are affected by CVE-2025-43371?
CVE-2025-43371 affects Apple Xcode versions up to and including 26.0.
What type of issue is described in CVE-2025-43371?
CVE-2025-43371 describes a path handling issue that was addressed with improved validation in Apple products.
Is CVE-2025-43371 related to open source code?
Yes, CVE-2025-43371 is a vulnerability found in open source code with Apple Software being among the affected projects.