CVE-2023-41991
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- September 06, 2023
- Published Date
- September 21, 2023
- Last Updated
- February 04, 2025
- Vendor
- Apple
- Product
- iOS and iPadOS, macOS
- Description
- A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVSS Scores
CVSS v3.1
5.5 - MEDIUM
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
SSVC Information
- Exploitation
- active
- Technical Impact
- partial
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2023-09-25 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
Zenyith/CVE-2023-41991
Type: github • Created: 2023-11-28 23:59:40 UTC • Stars: 2