CVE-2023-41991
KEVmassImproper Certificate Validation Bypass in Apple iOS, iPadOS, and macOS
CISA: Apple Multiple Products Improper Certificate Validation Vulnerability
Apple's September 2023 security updates fix a certificate validation flaw (CWE-295) in iOS, iPadOS, and macOS that allowed a malicious app to bypass signature validation. The bug is exploited locally: a victim must run or install a crafted app (local attack vector with user interaction per the CVSS scoring), and the flawed validation lets that app masquerade as legitimately signed code. A successful attacker gains high integrity impact, defeating Apple's signature checks so malicious code can run or persist as if it were properly signed. Users of iOS and iPadOS versions before 16.7 and macOS Ventura versions before 13.6 are affected. The flaw was exploited in the wild before the patch (Apple confirmed active exploitation of iOS prior to 16.7), it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, and related reporting around this disclosure ties the Apple zero-days to Predator commercial spyware campaigns.
What to do: Update iPhones and iPads to iOS 16.7 / iPadOS 16.7 (or later) and Macs to macOS Ventura 13.6 (or later) immediately, prioritizing high-risk users such as journalists, activists, and officials given the spyware-linked in-the-wild exploitation. Because the bug is in CISA's KEV catalog, patch promptly to meet federal remediation timelines, verify device versions in Settings/About, and hunt for indicators of spyware compromise on devices that remained on pre-16.7 iOS.
| Apple iPhone OS (iOS) | iOS versions prior to 16.7 |
| Apple iPadOS | iPadOS versions prior to 16.7 |
| Apple macOS Ventura | macOS Ventura versions prior to 13.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos
- Weakness
- CWE-295
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N