CVE-2022-48618
KEVmassPointer Authentication Bypass in Apple iOS, iPadOS, macOS, tvOS and watchOS
CISA: Apple Multiple Products Memory Corruption Vulnerability
CVE-2022-48618 is a time-of-check/time-of-use (TOCTOU, CWE-367) memory-corruption flaw in Apple's operating systems that an attacker with arbitrary read and write capability can use to bypass Pointer Authentication (PAC), Apple's hardware-based mitigation that cryptographically signs pointers to defeat common exploit techniques. It is a local, low-privilege, high-complexity flaw (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N), so it is typically chained after another vulnerability that first grants an arbitrary memory read/write primitive rather than exploited on its own. By defeating PAC, the attacker removes a key defense that normally limits the reliability of memory-corruption exploits, making it easier to turn arbitrary memory access into full code execution on the device. Affected users are those running iOS/iPadOS prior to 16.2, macOS Ventura prior to 13.1, watchOS prior to 9.2, or tvOS prior to 16.2. Apple reported the flaw was already exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-31, confirming in-the-wild exploitation; no public proof-of-concept is known.
What to do: Upgrade to iOS/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2 and tvOS 16.2 or later, prioritizing iPhones and iPads still running iOS below 15.7.1, which Apple confirmed were exploited. Inventory Apple endpoints via MDM/UEM and treat the KEV listing as a patching deadline per CISA's required action. Note that this flaw is typically chained after another bug granting arbitrary read/write, so ensure the full Apple security-update backlog is applied rather than treating PAC bypass in isolation.
| Apple iOS (iPhone OS) | Prior to 16.2 (exploitation reported against versions of iOS released before iOS 15.7.1) |
| Apple iPadOS | Prior to 16.2 |
| Apple macOS | macOS Ventura prior to 13.1 |
| Apple watchOS | Prior to 9.2 |
| Apple tvOS | Prior to 16.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
- Affected
- Apple Multiple Products
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, macos, tvos, watchos
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H