HIGH

CVE-2022-48618

Apple Ipados 2024-01-09 CVSS v3.1
CVSS
7
KEV

Description

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.

Summary dbcve.org

This is a Pointer Authentication (PAC) bypass vulnerability in Apple operating systems. PAC is an ARM security feature that cryptographically signs pointers to prevent exploitation of memory corruption bugs. The vulnerability allows an attacker with arbitrary read/write capability to bypass this protection mechanism, potentially enabling kernel-level code execution or jailbreak-style attacks.

Mitigation

Apply vendor security updates: iOS 16.2/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2, tvOS 16.2 or later. For older iOS devices, ensure at minimum iOS 15.7.1 is applied.

Weakness (CWE)

CWE-367

EPSS Score

0.49%
Probability of exploitation in next 30 days
40.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE