First published: Tue Jan 26 2021(Updated: )
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files on the host device while running an app that uses on-demand resources with Xcode.
Credit: product-security@apple.com Theodore Dubois @tblodt
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Xcode | <12.4 | |
Apple Xcode | <12.4 | 12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1800 is a vulnerability in Xcode IDE that allows a malicious application to access arbitrary files on the host device.
The severity of CVE-2021-1800 is medium with a CVSS score of 5.5.
CVE-2021-1800 affects Xcode by allowing a malicious application to access arbitrary files on the host device while running an app that uses on-demand resources.
CVE-2021-1800 is fixed in Xcode 12.4, so users should update to this version to address the vulnerability.
More information about CVE-2021-1800 can be found on the Apple support page: https://support.apple.com/en-us/HT212153