#VU81041 Improper Verification of Cryptographic Signature in Apple iOS and iPadOS - CVE-2023-41991
Published: September 21, 2023 / Updated: February 21, 2025
Apple iOS
iPadOS
Apple Inc.
Description
The vulnerability allows a remote attacker application to bypass implemented security restrictions.
The vulnerability exists due to improper verification of cryptographic signature within the Security component. A remote attacker can create a specially crafted application that can bypass signature validation process, trick the victim into installing it and compromise the affected system.
Note, the vulnerability is being actively exploited in the wild.