Embarcadero just made a hotfix for Delphi/RADStudio 10.2 Tokyo available, which fixes several debugger issues and – important for you C++ guys – it fixes a string related security issue, which could potentially overwrite memory with affected scanf and scanf_s methods.
https://community.embarcadero.com/blogs/entry/april-2017-rad-studio-10-2-hotfix-for-toolchain-issues