Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj3m-2r8f-m4x9

Опубликовано: 21 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A certificate validation issue was addressed. This issue is fixed in iOS 16.7 and iPadOS 16.7, OS 17.0.1 and iPadOS 17.0.1, watchOS 9.6.3, macOS Ventura 13.6, watchOS 10.0.1. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

A certificate validation issue was addressed. This issue is fixed in iOS 16.7 and iPadOS 16.7, OS 17.0.1 and iPadOS 17.0.1, watchOS 9.6.3, macOS Ventura 13.6, watchOS 10.0.1. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

EPSS

Процентиль: 87%
0.0348
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A malicious app may be able to bypass signature validation. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость компонента Security операционных систем iOS, watchOS, iPadOS и macOS, позволяющая нарушителю обойти проверку цифровой подписи

EPSS

Процентиль: 87%
0.0348
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-295