Junglewise Threat Intelligence

CVE-2023-41991: Apple Multiple Products Improper Certificate Validation Vulnerability

CVE-2023-41991 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2023-09-25

Technologies: Apple iPadOS, Apple watchOS, Apple macOS, Apple Multiple Products. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability. A malicious app can exploit this issue to bypass signature validation, potentially allowing the execution of unsigned or improperly signed code.

Affected products

  • Apple iOS before 16.7, 17.0
  • Apple iPadOS before 16.7, 17.0
  • Apple macOS 13.0 to before 13.6
  • Apple watchOS before 9.6.3, 10.0.0

Timeline

  • 2023-09-25: disclosed
  • 2023-09-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-25: patched: Fixed in macOS Ventura 13.6, iOS 16.7, and iPadOS 16.7
  • exploited: Apple is aware of reports that this issue may have been actively exploited against versions of iOS before iOS 16.7.

Related threats