A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
References
Link | Resource |
---|---|
https://support.apple.com/en-us/HT213927 | Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT213931 | Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT213927 | Release Notes Vendor Advisory |
https://support.apple.com/en-us/HT213931 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:22
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.apple.com/en-us/HT213927 - Release Notes, Vendor Advisory | |
References | () https://support.apple.com/en-us/HT213931 - Release Notes, Vendor Advisory |
10 Jan 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Nov 2023, 04:21
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Oct 2023, 12:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:* cpe:2.3:o:apple:ipados:17.0:*:*:*:*:*:*:* |
12 Oct 2023, 02:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:apple:watchos:10.0.0:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipad_os:17.0:*:*:*:*:*:*:* |
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
First Time |
Apple ipados
|
|
References | (MISC) https://support.apple.com/en-us/HT213931 - Release Notes, Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213927 - Release Notes, Vendor Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Oct/5 - Mailing List, Third Party Advisory |
03 Oct 2023, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Sep 2023, 15:19
Type | Values Removed | Values Added |
---|---|---|
Summary | A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. | |
References |
|
25 Sep 2023, 16:17
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://support.apple.com/en-us/HT213926 - Vendor Advisory | |
References | (MISC) https://support.apple.com/kb/HT213926 - Vendor Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Sep/15 - Third Party Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213927 - Vendor Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Sep/17 - Third Party Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Sep/14 - Third Party Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213929 - Vendor Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213931 - Vendor Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Sep/19 - Third Party Advisory | |
References | (MISC) https://support.apple.com/en-us/HT213928 - Vendor Advisory | |
References | (MISC) http://seclists.org/fulldisclosure/2023/Sep/16 - Third Party Advisory | |
CPE | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:10.0.0:*:*:*:*:*:*:* cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* cpe:2.3:o:apple:ipad_os:17.0:*:*:*:*:*:*:* cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-295 | |
First Time |
Apple
Apple ipad Os Apple watchos Apple iphone Os Apple macos |
23 Sep 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Sep 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Sep 2023, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-21 19:15
Updated : 2024-11-21 08:22
NVD link : CVE-2023-41991
Mitre link : CVE-2023-41991
CVE.ORG link : CVE-2023-41991
JSON object : View
Products Affected
apple
- iphone_os
- macos
- ipados
CWE
CWE-295
Improper Certificate Validation