The OCSP client in Apple iOS before 9.1 does not check for certificate expiry, which allows remote attackers to spoof a valid certificate by leveraging access to a revoked certificate.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Iphone_os |
Apple |
* |
9.0.2 (including) |
References