CVE-2023-41991: Apple Multiple Products Improper Certificate Validation Vulnerability
Medium severity, CVSS 5.5. Actively exploited: in CISA KEV since 2023-09-25. EPSS: 13.4% chance of exploitation in the next 30 days.
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Affected products
- Apple iPadOS: before 16.7 (fixed in 16.7); version 17.0 only
- Apple iPhone OS: before 16.7 (fixed in 16.7); version 17.0 only
- Apple macOS: from 13.0, before 13.6 (fixed in 13.6)
Published 2023-09-21. Last modified 2026-06-17.