QID 376606

Date Published: 2022-05-19

QID 376606: Apple Xcode Prior to 13.4 Vulnerability (HT213261)

Apple Xcode is an integrated development environment (IDE) for macOS containing a suite of software development tools developed by Apple.

CVE-2022-24765: On multi-user machines Git users might find themselves unexpectedly in a Git worktree

CVE-2022-26747: An app may be able to gain elevated privileges

Affected Versions:
Apple Xcode all versions prior to 13.4
Note: Xcode 13.4 is only available for: macOS Monterey 12 or later

QID Detection Logic (Authenticated): This checks for vulnerable versions of Apple Xcode under the Apple System Information.

An attacker may be able to cause privilege escalation.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Xcode 13.4 is only available for: macOS Monterey 12 or later

    Download XCode from here
    For more information please refer to HT213261

    Vendor References

    CVEs related to QID 376606

    Software Advisories
    Advisory ID Software Component Link
    HT213261 URL Logo support.apple.com/en-us/HT213261