⚠ Actively exploited
Added to CISA KEV on 2023-09-25. Federal agencies required to patch by 2023-10-16. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..
CVE-2023-41991 — Improper Certificate Validation in Apple IOS AND Ipados
Severity
5.5MEDIUMNVD
EPSS
3.2%
top 12.94%
CISA KEV
KEV
Added 2023-09-25
Due 2023-10-16
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 21
KEV addedSep 25
KEV dueOct 16
Latest updateDec 3
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages9 packages
🔴Vulnerability Details
2📋Vendor Advisories
6🕵️Threat Intelligence
15Bleepingcomputer
▶
Bleepingcomputer
▶