CVE-2022-48618: Apple Multiple Products Memory Corruption Vulnerability
Accessibility. A logic issue was addressed with improved restrictions.
Other sources
Accounts. This issue was addressed with improved data protection.
— Apple
AMD. A memory corruption issue was addressed with improved input validation.
— Apple
AMD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability that allows an attacker with read and write capabilities to bypass Pointer Authentication.
— CISA
AppleAVD. An out-of-bounds write issue was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-42843
- CVE-2022-46694
- CVE-2022-42865
- CVE-2022-42848
- CVE-2022-46693
- CVE-2022-42851
- CVE-2022-42864
- CVE-2022-46690
- CVE-2022-42837
- CVE-2022-46689
- CVE-2022-46701
- CVE-2022-42842
- CVE-2022-42845
- CVE-2022-48618
- CVE-2022-40303
- CVE-2022-40304
- CVE-2022-42855
- CVE-2022-46695
- CVE-2022-42849
- CVE-2022-42866
- CVE-2022-46705
- CVE-2022-42867
- CVE-2022-46691
- CVE-2022-46692
- CVE-2022-42852
- CVE-2022-46696
- CVE-2022-46700
- CVE-2022-46698
- CVE-2022-46699
- CVE-2022-42863
- CVE-2022-42856
- CVE-2022-46717
- CVE-2022-42859
- CVE-2022-46703
- CVE-2022-42858
- CVE-2022-42847
- CVE-2022-42854
- CVE-2022-42853
- CVE-2022-35252
- CVE-2022-32942
- CVE-2022-46720
- CVE-2022-46710
- CVE-2022-46697
- CVE-2022-42861
- CVE-2022-42839
- CVE-2022-46716
- CVE-2022-46704
- CVE-2022-32943
- CVE-2022-42840
- CVE-2022-42862
- CVE-2022-24836
- CVE-2022-29181
- CVE-2022-46718
- CVE-2022-32919
- CVE-2022-46725
- CVE-2022-42841
- CVE-2022-43454
- CVE-2022-48610
- CVE-2022-46702
- CVE-2022-42850
- CVE-2022-42846
- CVE-2022-42844
- CVE-2024-21762
- CVE-2024-23108
- CVE-2024-23109
- CVE-2023-34992
- CVE-2022-42475
- CVE-2023-27997
Frequently Asked Questions
What is the severity of CVE-2022-48618?
CVE-2022-48618 is classified as a critical vulnerability due to its potential for exploitation leading to memory corruption and unauthorized access.
How do I fix CVE-2022-48618?
To fix CVE-2022-48618, users should update affected Apple and Fortinet products to the latest versions as specified by their vendors.
What products are affected by CVE-2022-48618?
CVE-2022-48618 affects multiple products including Apple iOS, iPadOS, macOS, tvOS, watchOS, and Fortinet FortiOS.
What type of issue is CVE-2022-48618?
CVE-2022-48618 involves a logic issue leading to memory corruption and an out-of-bounds write vulnerability.
Has CVE-2022-48618 been exploited in the wild?
Yes, CVE-2022-48618 has been reported as actively exploited in the wild, emphasizing the urgency of applying patches.