AppleCVE-2026-65393
Apple Xcode: improper authorization
Medium5.5CVE-2026-65393 · Published Sep 14, 2026 · updated Sep 22, 2026
A permissions issue was addressed with improved validation. This issue is fixed in Xcode 27, macOS Golden Gate 27. An app may be able to access user-sensitive data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Xcode Product | < 27 | 27 |
| macOS Product | < 27 | 27 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-863
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 14 | Apple macOS: path traversal | Medium5.5 | 14.8.8+1 more |
| Sep 14 | Apple iOS and iPadOS: out-of-bounds read | Medium5.5 | 27+2 more |
| Sep 14 | A privacy issue was addressed with improved state management | High7.5 | 26.7+2 more |
| Sep 14 | Apple iOS and iPadOS: improper access control | Medium5.5 | 27+2 more |
| Sep 14 | Apple macOS: protection mechanism failure | Medium4.4 | 27 |
| Sep 14 | Apple macOS: path traversal | Medium5.5 | 15.8+2 more |