← לוח פגיעויות

CVE-2023-41991

בינונית 5.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Apple Multiple Products Improper Certificate Validation Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

מדדים

CVSS 3.1
5.5 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS — סבירות ניצול
5% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-295

מוצרים מושפעים

apple: ipados; apple: iphone os; apple: macos

קישורים