The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.1, watchOS 9.2, iOS 16.2 and iPadOS 16.2, tvOS 16.2. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of a report that this issue may have been exploited against versions of iOS released before iOS 15.7.1.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Accounts | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Amd | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Applemobilefileintegrity | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Bluetooth | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Bootcamp | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Coreservices | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Curl | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Driverkit | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Dyld | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Icloudphotolibrary | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Imageio | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Iohidfamily | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Iomobileframebuffer | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Itunesstore | — | — | Oct 14, 2024 | Jan 9, 2024 |
| Apple Osx Kernel | — | Upgrade macOS to the latest version | Jan 10, 2024 | Jan 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub