Overview
- Description
- A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
- Source
- product-security@apple.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
Known exploits
Data from CISA
- Vulnerability name
- Apple Multiple Products Improper Certificate Validation Vulnerability
- Exploit added on
- Sep 25, 2023
- Exploit action due
- Oct 16, 2023
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weaknesses
- nvd@nist.gov
- CWE-295
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CEB5BA1-7092-4ADE-B19F-FD34CB53CCC3", "versionEndExcluding": "16.7" }, { "criteria": "cpe:2.3:o:apple:ipados:17.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FD0EE39C-DEC4-475C-8661-5BD76457A39E" }, { "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FC8EB94-1D4F-4CE8-83D0-9086D1EBBC8F", "versionEndExcluding": "16.7" }, { "criteria": "cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "502CD624-FA22-4C7B-9CA3-53CA938BE1AB" }, { "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7A78DA60-AE3B-4B3C-B338-97DAFABEBB1F", "versionEndExcluding": "13.6", "versionStartIncluding": "13.0" } ], "operator": "OR" } ] } ]