January 31, 2024 · Applied Cybernetics Group
CVE-2022-48618 — Apple Multiple Products
Apple Multiple Products Memory Corruption Vulnerability
- Added to KEV
2024-01-31- Federal due date
2024-02-21- Vendor
- Apple
- Product
- Multiple Products
- EPSS
- 29.7th percentile (score 0.001, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-48618
CISA short description
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.