86 results (0.019 seconds)

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

31 Mar 2025 — This issue was addressed through improved state management. This issue is fixed in Xcode 16.3. An app may be able to overwrite arbitrary files. Xcode 16.3 addresses issues where a malicious app could access private information or overwrite arbitrary files. • https://support.apple.com/en-us/122380 • CWE-787: Out-of-bounds Write •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

31 Mar 2025 — The issue was addressed with improved checks. This issue is fixed in Xcode 16.3. A malicious app may be able to access private information. Xcode 16.3 addresses issues where a malicious app could access private information or overwrite arbitrary files. • https://support.apple.com/en-us/122380 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

28 Oct 2024 — This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data. • https://support.apple.com/en-us/121239 • CWE-276: Incorrect Default Permissions •

CVSS: 5.5EPSS: 0%CPEs: 7EXPL: 0

16 Sep 2024 — This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app may gain unauthorized access to Bluetooth. macOS Sequoia 15 addresses buffer overflow, bypass, cross site scripting, integer overflow, out of bounds access, out of bounds read, out of bounds write, and spoofing vulnerabilities. • https://support.apple.com/en-us/121238 •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

16 Sep 2024 — A privacy issue was addressed by removing sensitive data. This issue is fixed in Xcode 16. An attacker may be able to determine the Apple ID of the owner of the computer. Xcode 16 addresses unauthorized access issues. • https://support.apple.com/en-us/121239 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

16 Sep 2024 — This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain items. Xcode 16 addresses unauthorized access issues. • https://support.apple.com/en-us/121239 • CWE-863: Incorrect Authorization •

CVSS: 5.5EPSS: 3%CPEs: 1EXPL: 1

15 Mar 2024 — A logic issue was addressed with improved state management. Se abordó una cuestión de lógica con una mejor gestión de estado. • https://github.com/p1tsi/CVE-2024-23298.app •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

26 Sep 2023 — This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. Este problema se solucionó habilitando el tiempo de ejecución reforzado. Este problema se solucionó en Xcode 15. • http://seclists.org/fulldisclosure/2023/Oct/7 •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

26 Sep 2023 — The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, macOS Sonoma 14, Xcode 15. An app may be able to disclose kernel memory. El problema se solucionó mejorando el manejo de la memoria. Este problema se solucionó en tvOS 17, iOS 17 y iPadOS 17, macOS Sonoma 14, Xcode 15. • http://seclists.org/fulldisclosure/2023/Oct/10 •

CVSS: 7.8EPSS: 0%CPEs: 6EXPL: 0

26 Sep 2023 — This issue was addressed with improved checks. This issue is fixed in Xcode 15, tvOS 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to gain elevated privileges. Este problema se solucionó con controles mejorados. Este problema se solucionó en Xcode 15, tvOS 17, watchOS 10, iOS 17 y iPadOS 17, macOS Sonoma 14. • http://seclists.org/fulldisclosure/2023/Oct/10 •