⚠ Actively exploited
Added to CISA KEV on 2023-09-25. Federal agencies required to patch by 2023-10-16. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-41991Improper Certificate Validation in Apple IOS AND Ipados

Severity
5.5MEDIUMNVD
EPSS
3.2%
top 12.94%
CISA KEV
KEV
Added 2023-09-25
Due 2023-10-16
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 21
KEV addedSep 25
KEV dueOct 16
Latest updateDec 3
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

CVEListV5apple/macosunspecified13.6
NVDapple/macos13.013.6
NVDapple/ipados< 16.7+1
CVEListV5apple/ios_and_ipadosunspecified16.7

🔴Vulnerability Details

2
GHSA
GHSA-fj3m-2r8f-m4x9: A certificate validation issue was addressed2023-09-21
VulnCheck
Apple Multiple Products Improper Certificate Validation Vulnerability2023

📋Vendor Advisories

6
CISA
Apple Multiple Products Improper Certificate Validation Vulnerability2023-09-25
Apple
CVE-2023-41991: watchOS 9.6.32023-09-21
Apple
CVE-2023-41991: iOS 17.0.1 and iPadOS 17.0.12023-09-21
Apple
CVE-2023-41991: watchOS 10.0.12023-09-21
Apple
CVE-2023-41991: macOS Ventura 13.62023-09-21

🕵️Threat Intelligence

15
Mandiant
Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03
Mandiant
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03
Bleepingcomputer
Apple fixes WebKit zero-day exploited in &lsquo;extremely sophisticated&rsquo; attacks2025-03-11
Bleepingcomputer
Apple fixes zero-day exploited in &#039;extremely sophisticated&#039; attacks2025-02-10
Bleepingcomputer
Apple fixes this year&rsquo;s first actively exploited zero-day bug2025-01-27