CVE-2023-23524: Apple iPadOS
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A denial-of-service issue was addressed with improved input validation. This issue is fixed in tvOS 16.3.2, iOS 16.3.1 and iPadOS 16.3.1, watchOS 9.3.1, macOS Ventura 13.2.1. Processing a maliciously crafted certificate may lead to a denial-of-service.
Affected products
- Apple iPadOS: before 16.3.1 (fixed in 16.3.1)
- Apple iPhone OS: before 16.3.1 (fixed in 16.3.1)
- Apple macOS: before 13.2.1 (fixed in 13.2.1)
- Apple tvOS: before 16.3.2 (fixed in 16.3.2)
- Apple watchOS: before 9.3.1 (fixed in 9.3.1)
Published 2023-02-27. Last modified 2026-06-17.