CVE-2025-43370: Apple Xcode

Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.

A path handling issue was addressed with improved validation. This issue is fixed in Xcode 26. Processing an overly large path value may crash a process.

Affected products

  • Apple Xcode: before 26.0 (fixed in 26.0)

Published 2025-09-15. Last modified 2026-10-01.