CVE-2022-48618 - Apple Multiple Products Memory Corruption Vulnerability
Project:Apple
Product:Multiple Products
Date Added:2024-01-31Due Date:2024-02-21
Vulnerability Name
Apple Multiple Products Memory Corruption Vulnerability
Description
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.apple.com/en-us/HT213530, https://support.apple.com/en-us/HT213532, https://support.apple.com/en-us/HT213535, https://support.apple.com/en-us/HT213536
https://nvd.nist.gov/vuln/detail/CVE-2022-48618