QID 375873

Date Published: 2021-09-23

QID 375873: Apple Xcode Prior to 13 Vulnerability (HT212818)

Apple Xcode is an integrated development environment (IDE) for macOS containing a suite of software development tools developed by Apple.

A crafted git URL that contains a newline in it may cause credential information to be provided for the wrong host.

Affected Versions:
Apple Xcode all versions prior to 13
Note: Xcode 13 is only available for: macOS Big Sur 11.3 and later

QID Detection Logic (Authenticated): This checks for vulnerable versions of Apple Xcode under the Apple System Information.

A remote attacker may be able to cause arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Xcode 13 is only available for: macOS Big Sur 11.3 and later

    Download XCode from here
    For more information please refer to HT212818

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    HT212818 URL Logo support.apple.com/en-us/HT212818