CVE-2022-48618
Description
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
Summary dbcve.org
This is a Pointer Authentication (PAC) bypass vulnerability in Apple operating systems. PAC is an ARM security feature that cryptographically signs pointers to prevent exploitation of memory corruption bugs. The vulnerability allows an attacker with arbitrary read/write capability to bypass this protection mechanism, potentially enabling kernel-level code execution or jailbreak-style attacks.
Mitigation
Apply vendor security updates: iOS 16.2/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2, tvOS 16.2 or later. For older iOS devices, ensure at minimum iOS 15.7.1 is applied.