A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
2023-09-21T19:15:11.283
2025-02-10T17:53:40.387
Analyzed
CVSSv3.1: 5.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | ipados | < 16.7 | Yes |
Operating System | apple | ipados | 17.0 | Yes |
Operating System | apple | iphone_os | < 16.7 | Yes |
Operating System | apple | iphone_os | 17.0 | Yes |
Operating System | apple | macos | < 13.6 | Yes |