CVE-2025-43504: Apple Xcode

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A buffer overflow was addressed with improved bounds checking. This issue is fixed in Xcode 26.1. A user in a privileged network position may be able to cause a denial-of-service.

Affected products

  • Apple Xcode: before 26.1 (fixed in 26.1)

Published 2025-11-04. Last modified 2026-06-17.