Skip to content
COOEY

EXPOSURES › CVE-2023-41991

CVE-2023-41991

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-41991 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 exploited-in-wildunpatched

Apple iOS, iPadOS, macOS, and watchOS improper certificate validation vulnerability

Apple's iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that allows malicious apps to bypass signature validation. This can lead to remote code execution and should be patched immediately to prevent exploitation.

Shame score — This vulnerability allows remote code execution and is actively exploited, leading to significant security risks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, macOS, and watchOS contain an improper certificate validation vulnerability that can allow a malicious app to bypass signature validation.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.