Impact
Apple discovered a certificate validation flaw that can allow an attacker who controls a compromised intermediate certificate authority to issue certificates with arbitrary extended key usage values as trusted by Apple operating systems, enabling the attacker to impersonate legitimate services or devices, conduct man‑in‑the‑middle attacks, or bypass integrity checks. Based on the description, it is inferred that the attacker would need access to a compromised intermediate certificate authority to issue the certificates.
Affected Systems
The vulnerability affects Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. All releases prior to the fixes—iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, and watchOS 27—remain vulnerable.
Risk and Exploitability
With a CVSS score of 9.1, this flaw is classified as critical severity. The EPSS score of < 1% indicates a very low but non-zero probability of exploitation in the wild. It is not listed in the CISA KEV catalog, so there is no reported active exploitation. An attacker who has control over a compromised intermediate certificate authority can issue certificates with arbitrary extended key usage values and have them trusted by Apple operating systems. Based on the description, it is inferred that the attacker’s only requirement is the ability to generate certificates under a compromised CA, with no additional software or privileged local access needed. This can enable impersonation of legitimate services or devices, man‑in‑the‑middle attacks, or bypass integrity checks.
OpenCVE Enrichment