Back

MEDIUM

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions

Published Jan 23, 2024

Description

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macOS Ventura 13.6.5, tvOS 17.3, watchOS 10.3. An attacker may be able to decrypt legacy RSA PKCS#1 v1.5 ciphertexts without having the private key.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (23)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apple
Published Jan 23, 2024
Updated Apr 2, 2026
Reserved Jan 12, 2024
CISA Vulnrichment
Updated Dec 4, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a