CVE-2023-41991: Apple Multiple Products Improper Certificate Validation Vulnerability
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Other sources
App Store. The issue was addressed with improved handling of protocols.
— Apple
Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.
— CISA
Apple Neural Engine. A use-after-free issue was addressed with improved memory management.
— Apple
Apple Neural Engine. An out-of-bounds read was addressed with improved input validation.
— Apple
Apple Neural Engine. The issue was addressed with improved handling of caches.
— Apple
Credit
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2023-41992
- CVE-2023-41991
- CVE-2023-40412
- CVE-2023-40409
- CVE-2023-41071
- CVE-2023-40410
- CVE-2023-38612
- CVE-2023-41232
- CVE-2023-40406
- CVE-2023-40420
- CVE-2023-41984
- CVE-2023-41981
- CVE-2023-41073
- CVE-2023-40454
- CVE-2023-40403
- CVE-2023-40427
- CVE-2023-41063
- CVE-2023-40452
- CVE-2023-41996
- CVE-2023-41070
- CVE-2023-41968
- CVE-2023-40448
- CVE-2023-40438
- CVE-2023-40395
- CVE-2023-41068
- CVE-2023-40401
- CVE-2023-35990
- CVE-2023-41993
- CVE-2023-42969
- CVE-2023-42961
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-41991.
What is the severity of CVE-2023-41991?
The severity of CVE-2023-41991 is not specified in the provided information.
Which Apple products are affected by CVE-2023-41991?
macOS Ventura 13.6, iOS up to 16.7, iPadOS up to 16.7, watchOS up to 9.6.3, iOS up to 17.0.1, and iPadOS up to 17.0.1 are affected by CVE-2023-41991.
How can a malicious app exploit CVE-2023-41991?
A malicious app may be able to bypass signature validation.
Is there a fix for CVE-2023-41991?
Yes, this issue is fixed in iOS 16.7 and iPadOS 16.7, OS 17.0.1 and iPadOS 17.0.1, watchOS 9.6.3, and macOS Ventura 13.6.