CVE-2026-28890: Medium severity Apple Xcode vulnerability
Published Mar 24, 2026
·Updated
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 26.4. An app may be able to cause unexpected system termination.
Other sources
otool. An out-of-bounds read was addressed with improved bounds checking.
— Apple
Credit
Nathaniel Oh@@calysteon, Mihai Marin
Affected Software
2 affected componentsFixes available
Apple Xcode<26.4
26.4
Apple Xcode<26.4
Event History
Mar 24, 2026
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Mar 25, 2026
CVE Published
via MITRE·12:32 AM
Data Sourced
via MITRE·12:32 AM
DescriptionWeakness
Data Sourced
via NVD·01:17 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28890?
CVE-2026-28890 is classified as a high severity vulnerability due to its potential to cause unexpected system termination.
2
How do I fix CVE-2026-28890?
To fix CVE-2026-28890, update to Xcode version 26.4 or later.
3
What type of vulnerability is CVE-2026-28890?
CVE-2026-28890 is an out-of-bounds read vulnerability that was addressed with improved bounds checking.
4
Which software is affected by CVE-2026-28890?
CVE-2026-28890 affects Apple Xcode versions earlier than 26.4.
5
Can CVE-2026-28890 lead to system crashes?
Yes, CVE-2026-28890 may allow an app to cause unexpected system termination.