Junglewise Threat Intelligence

CVE-2026-65393: Apple Xcode permissions bypass in IDE

CVE-2026-65393 · Severity: medium · CVSS 5.5 · Published 2026-09-14

Technologies: Apple macOS, Apple macOS Golden Gate. Vendors: Apple.

Executive brief

Xcode is Apple's integrated development environment used by software developers to build applications. A permissions issue allows an app to access user-sensitive data that should be protected, potentially exposing personal information to malicious applications.

Technical details

A permissions issue in Xcode's IDE component was resolved through improved validation. The vulnerability allows an application to bypass access restrictions and read user-sensitive data that should be protected. The attack requires local access to a system with Xcode installed and a malicious app running in the Xcode environment. This vulnerability affects Xcode 27 and has been patched in the same version released on September 14, 2026.

Affected products

  • Apple Xcode before 27
  • Apple macOS Golden Gate before 27

Timeline

  • 2026-09-14: disclosed: CVE-2026-65393 disclosed in Xcode 27 and macOS Golden Gate 27 release notes
  • 2026-09-14: patched: Fixed in Xcode 27 and macOS Golden Gate 27

References

Related threats