CVE-2026-28889: Medium severity Apple Xcode vulnerability
Published Mar 24, 2026
·Updated
A permissions issue was addressed with additional restrictions. This issue is fixed in Xcode 26.4. An app may be able to read arbitrary files as root.
Other sources
otool. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Simulator. A permissions issue was addressed with additional restrictions.
— Apple
Credit
Nathaniel Oh@@calysteon, Mihai Marin
Affected Software
2 affected componentsFixes available
Apple Xcode<26.4
26.4
Apple Xcode<26.4
Event History
Mar 24, 2026
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Mar 25, 2026
CVE Published
via MITRE·12:31 AM
Data Sourced
via MITRE·12:31 AM
DescriptionWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28889?
CVE-2026-28889 has medium severity due to its potential to allow apps to read arbitrary files as root.
2
How do I fix CVE-2026-28889?
To fix CVE-2026-28889, update Xcode to version 26.4 or later.
3
Which versions of Xcode are affected by CVE-2026-28889?
Xcode versions prior to 26.4 are affected by CVE-2026-28889.
4
What types of issues does CVE-2026-28889 address?
CVE-2026-28889 addresses a permissions issue and an out-of-bounds read vulnerability.
5
Can CVE-2026-28889 affect the Simulator in Xcode?
Yes, CVE-2026-28889 includes restrictions that directly affect the Simulator in Xcode.