EXPOSURES › CVE-2022-48618
CVE-2022-48618
HIGH ⌖ ON CISA KEV · EXPLOITEDApple devices are vulnerable to a TOCTOU memory corruption flaw that bypasses Pointer Authentication, allowing attackers to bypass security controls on iOS, macOS, and other platforms.
This TOCTOU vulnerability in Apple's operating systems allows attackers to bypass Pointer Authentication, potentially leading to privilege escalation or remote code execution if an attacker can exploit the memory corruption. DIB organizations must ensure all Apple devices are patched immediately to prevent unauthorized access to sensitive systems, as this flaw is actively exploited and poses a significant security risk.
Shame score — The vulnerability is actively exploited and affects multiple Apple products, requiring urgent patching to prevent potential security breaches.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.