← back
CVE-2022-48618

CVE-2022-48618

CVSS 7 HIGHEPSS 0.5%● KEVCWE-367
Vexday Risk Score
51Attention
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7EPSS 0.5%KEV simPoC Nuclei Metasploit Patch
Lifecycle
09 Jan 2024Published on NVD
31 Jan 2024Active exploitation (CISA KEV)
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A security mechanism called Pointer Authentication, which protects against certain types of attacks on Apple devices, could be bypassed if an attacker gains read and write access to device memory. This is serious because it could allow attackers to run malicious code without being detected.

Technical detail

A time-of-check-time-of-use (TOCTOU) race condition in Pointer Authentication implementation allows an attacker with arbitrary memory read/write capability to bypass the authentication checks protecting code pointers. This requires prior memory access but could enable privilege escalation or code execution bypass on affected iOS, iPadOS, watchOS, and tvOS versions prior to the specified patches.

Summary generated and translated by AI from the official description.
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →