CVE Published: 21/09/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: apple |
Vendor: Apple |
Product: iOS and iPadOS Status : PUBLISHED
CVE-2023-41991 Description
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
CWE-ID: CWE Name: A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7. Source: Apple
Common Attack Pattern Enumeration and Classification (CAPEC)