ZeroHour

CVE-2022-48618

KEVmass

Pointer Authentication Bypass in Apple iOS, iPadOS, macOS, tvOS and watchOS

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.0 high
EPSS
<1%p41
Published
()
KEV added
AI analysis

CVE-2022-48618 is a time-of-check/time-of-use (TOCTOU, CWE-367) memory-corruption flaw in Apple's operating systems that an attacker with arbitrary read and write capability can use to bypass Pointer Authentication (PAC), Apple's hardware-based mitigation that cryptographically signs pointers to defeat common exploit techniques. It is a local, low-privilege, high-complexity flaw (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N), so it is typically chained after another vulnerability that first grants an arbitrary memory read/write primitive rather than exploited on its own. By defeating PAC, the attacker removes a key defense that normally limits the reliability of memory-corruption exploits, making it easier to turn arbitrary memory access into full code execution on the device. Affected users are those running iOS/iPadOS prior to 16.2, macOS Ventura prior to 13.1, watchOS prior to 9.2, or tvOS prior to 16.2. Apple reported the flaw was already exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-31, confirming in-the-wild exploitation; no public proof-of-concept is known.

What to do: Upgrade to iOS/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2 and tvOS 16.2 or later, prioritizing iPhones and iPads still running iOS below 15.7.1, which Apple confirmed were exploited. Inventory Apple endpoints via MDM/UEM and treat the KEV listing as a patching deadline per CISA's required action. Note that this flaw is typically chained after another bug granting arbitrary read/write, so ensure the full Apple security-update backlog is applied rather than treating PAC bypass in isolation.

Affected
Apple iOS (iPhone OS)Prior to 16.2 (exploitation reported against versions of iOS released before iOS 15.7.1)
Apple iPadOSPrior to 16.2
Apple macOSmacOS Ventura prior to 13.1
Apple watchOSPrior to 9.2
Apple tvOSPrior to 16.2
Estimated exposure
mass>1 billion devices (combined Apple iPhone/iPad/Mac/Apple Watch/Apple TV install base, minus already-updated devices) — Apple's iPhone/iPad active install base alone exceeds one billion devices, with macOS, Apple Watch and Apple TV adding hundreds of millions more, so even the fraction of fleets not yet patched to the fixed versions represents a very large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, tvos, watchos
Weakness
CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news