ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Apple improper authentication bug to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2022-48618

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-48618
Pointer Authentication Bypass in Apple iOS, iPadOS, macOS, tvOS and watchOS

CVE-2022-48618 is a time-of-check/time-of-use (TOCTOU, CWE-367) memory-corruption flaw in Apple's operating systems that an attacker with arbitrary read and write capability can use to bypass Pointer Authentication (PAC), Apple's hardware-based mitigation that cryptographically signs pointers to defeat common exploit techniques. It is a local, low-privilege, high-complexity flaw (CVSS 3.1: 7.0, AV:L/AC:H/PR:L/UI:N), so it is typically chained after another vulnerability that first grants an arbitrary memory read/write primitive rather than exploited on its own. By defeating PAC, the attacker removes a key defense that normally limits the reliability of memory-corruption exploits, making it easier to turn arbitrary memory access into full code execution on the device. Affected users are those running iOS/iPadOS prior to 16.2, macOS Ventura prior to 13.1, watchOS prior to 9.2, or tvOS prior to 16.2. Apple reported the flaw was already exploited against versions of iOS released before iOS 15.7.1, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-31, confirming in-the-wild exploitation; no public proof-of-concept is known.

Do: Upgrade to iOS/iPadOS 16.2, macOS Ventura 13.1, watchOS 9.2 and tvOS 16.2 or later, prioritizing iPhones and iPads still running iOS below 15.7.1, which Apple confirmed were exploited. Inventory Apple endpoints via MDM/UEM and treat the KEV listing as a patching deadline per CISA's required action. Note that this flaw is typically chained after another bug granting arbitrary read/write, so ensure the full Apple security-update backlog is applied rather than treating PAC bypass in isolation.

7.0<1% KEV
  • Apple iOS (iPhone OS) Prior to 16.2 (exploitation reported against versions of iOS released before iOS 15.7.1)
  • Apple iPadOS Prior to 16.2
  • Apple macOS macOS Ventura prior to 13.1
  • +2 more
mass>1 billion devices (combined Apple iPhone/iPad/Mac/Apple Watch/Apple TV install base, minus already-updated devices)
Full article231 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple improper authentication bug to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple improper authentication bug, tracked as CVE-2022-48618, to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability can allow an attacker with arbitrary read and write capability to bypass Pointer Authentication.

The IT giant addressed the issue with improved checks. The flaw is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2.

Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.

“An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.” reads the advisory.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by February 21, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – CISA, Apple)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/158412/security/cisa-apple-bug-to-known-exploited-vulnerabilities-catalog.html