← Browse

CVE-2022-48618

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
0.5%
41.0th percentile
CISA KEV
Listed
Added 2024-01-31 · patch by 2024-02-21
Weakness / dates
Published — · modified —

Timeline

Description

Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.

Official: NVD · CVE.org