Xhyve is a lightweight hypervisor and virtualization project for macOS that presents a narrow but specialized attack surface through its single core product. The vulnerabilities associated with the project center on memory-safety issues including NULL-pointer dereferences, out-of-bounds writes, and stack-based buffer overflows, typical of native code hypervisor implementations where low-level memory management directly shapes the security boundary. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xhyve Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36660CRITICAL xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify(). | Sep 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36661MEDIUM xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_read(). This vulnerability allows attackers to cause a Denial of Service via unsp | Sep 7, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-36659MEDIUM xhyve commit dfbe09b was discovered to contain a NULL pointer dereference via the component vi_pci_write(). This vulnerability allows attackers to cause a Denial of Service via uns | Sep 7, 2022 | 6.5 | 22 | NO | NO |
CVE-2022-35867MEDIUM This vulnerability allows local attackers to escalate privileges on affected installations of xhyve. An attacker must first obtain the ability to execute high-privileged code on th | Aug 3, 2022 | 6.7 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xhyve Project.
Media articles that mention a CVE ID that affects a product developed by Xhyve Project — matched by CVE ID, not by vendor name.