ZeroHour
Product

Xcode

2 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

Researchers disclosed an integer underflow in Apple's Mach-O archive parser that lets crafted static libraries crash Xcode builds or leak process memory.

SecureLayer7 disclosed an integer underflow in the mach_o::Archive::Entry::name() function in Apple's open-source dyld project, reported to Apple Product Security on May 23, 2026, with no public patch after more than 90 days. Crafted static archives (.a files) cause the parser's unsigned index to wrap to SIZE_MAX, producing SIGSEGV crashes in the ld-prime linker, out-of-bounds reads that may print adjacent memory to stderr, or SIGABRT in libtool and ranlib. The modern parser is used by ld-prime, the default linker for arm64, arm64e, and x86_64 since Xcode 15, while legacy ld-classic is unaffected. Crafted archives need only be processed, creating supply-chain risk via vendored SDKs, binary dependencies, and CI pipelines.

GBHackers · 5d agoVulnerability1

Xcode 27 RC (27A266a)

Apple released the Xcode 27 release candidate (build 27A266a) via its developer releases page.

Apple has published a release candidate of Xcode 27, build 27A266a, on its developer releases page. The listing contains no security notes, CVEs, or vulnerability details in the available text. This is a routine vendor software release ahead of the final Xcode 27 version.

Apple software releasesupdated · 1d agofirst · 6d agoAdvisory 2 sources

Xcode 27 beta 6 (27A5252f)

Apple shipped Xcode 27 beta 6 (build 27A5252f) with downloads and release notes on its developer portal.

Apple released the sixth beta of Xcode 27, build 27A5252f, via its developer downloads page. The announcement is a routine beta release note with no vulnerability, patch, or security details included. It matters mainly to developers tracking Apple platform tooling ahead of the next OS releases.

Apple software releases · 22d agoOther

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.