CVE-2023-40440: Apple macOS
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
This issue was addressed with improved state management of S/MIME encrypted emails. This issue is fixed in macOS Monterey 12.6.8. A S/MIME encrypted email may be inadvertently sent unencrypted.
Affected products
- Apple macOS: from 12.0.0, before 12.6.8 (fixed in 12.6.8)
Published 2023-09-12. Last modified 2026-06-17.