A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Amd | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Apache | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Applegraphicscontrol | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Applescript | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Avevideoencoder | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Contacts | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Cvms | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Facetime | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Intelgraphicsdriver | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Iokit | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | May 26, 2022 |
| Apple Osx Kernel | — | Upgrade macOS to the latest version | Jun 1, 2022 | May 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub