QID 375511

Date Published: 2021-04-28

QID 375511: Apple Xcode Prior To 12.5 Vulnerability (HT212320)

Apple Xcode is an integrated development environment (IDE) for macOS containing a suite of software development tools developed by Apple.

A crafted git URL that contains a newline in it may cause credential information to be provided for the wrong host.

Affected Versions:
Apple Xcode all versions prior to 12.5
Note: Xcode 12.5 is only available for: macOS Big Sur 11 and later

QID Detection Logic (Authenticated): This checks for vulnerable versions of Apple Xcode under the Apple System Information.

A remote attacker may be able to cause arbitrary code execution.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    Xcode 12.5 is only available for: macOS Big Sur 11 and later

    Download XCode from here
    For more information please refer to HT212320

    Vendor References

    CVEs related to QID 375511

    Software Advisories
    Advisory ID Software Component Link
    HT212320 URL Logo idmsa.apple.com/IDMSWebAuth/signin?appIdKey=891bd3417a7776362562d2197f89480a8547b108fd934911bcbea0110d07f757&path=%2Fdownload%2F&rv=1