ZeroHour

CVE-2023-41991

KEVmass

Improper Certificate Validation Bypass in Apple iOS, iPadOS, and macOS

CISA: Apple Multiple Products Improper Certificate Validation Vulnerability

CVSS 3.1
5.5 medium
EPSS
5%p91
Published
()
KEV added
AI analysis

Apple's September 2023 security updates fix a certificate validation flaw (CWE-295) in iOS, iPadOS, and macOS that allowed a malicious app to bypass signature validation. The bug is exploited locally: a victim must run or install a crafted app (local attack vector with user interaction per the CVSS scoring), and the flawed validation lets that app masquerade as legitimately signed code. A successful attacker gains high integrity impact, defeating Apple's signature checks so malicious code can run or persist as if it were properly signed. Users of iOS and iPadOS versions before 16.7 and macOS Ventura versions before 13.6 are affected. The flaw was exploited in the wild before the patch (Apple confirmed active exploitation of iOS prior to 16.7), it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, and related reporting around this disclosure ties the Apple zero-days to Predator commercial spyware campaigns.

What to do: Update iPhones and iPads to iOS 16.7 / iPadOS 16.7 (or later) and Macs to macOS Ventura 13.6 (or later) immediately, prioritizing high-risk users such as journalists, activists, and officials given the spyware-linked in-the-wild exploitation. Because the bug is in CISA's KEV catalog, patch promptly to meet federal remediation timelines, verify device versions in Settings/About, and hunt for indicators of spyware compromise on devices that remained on pre-16.7 iOS.

Affected
Apple iPhone OS (iOS)iOS versions prior to 16.7
Apple iPadOSiPadOS versions prior to 16.7
Apple macOS VenturamacOS Ventura versions prior to 13.6
Estimated exposure
masson the order of hundreds of millions of iOS/iPadOS devices (the unpatched share of Apple's >1B active-device base at disclosure) plus macOS Ventura fleets — Apple's active iPhone/iPad/Mac install base exceeds a billion devices, and typical adoption curves at disclosure time leave hundreds of millions of devices short of the just-released 16.7/13.6 fixes, so this is an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos
Weakness
CWE-295
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news