VYPR
Medium severity5.5CISA KEVNVD Advisory· Published Sep 21, 2023· Updated Jun 17, 2026

CVE-2023-41991

CVE-2023-41991

Description

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Apple Inc./Ipados3 versions
    cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <16.7
    • cpe:2.3:o:apple:ipados:17.0:*:*:*:*:*:*:*
    • (no CPE)range: before 16.7
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*range: <16.7
    • cpe:2.3:o:apple:iphone_os:17.0:*:*:*:*:*:*:*
  • Apple Inc./macOS3 versions
    cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: >=13.0,<13.6
    • (no CPE)range: unspecified
    • (no CPE)range: before 13.6
  • Range: unspecified
  • Apple Inc./iOSllm-fuzzy
    Range: before 16.7

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.