{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2022-48618",
  "revision": 1,
  "title": "Apple — pointer authentication defeated by a race",
  "summary": "A check-then-use race in Apple's kernel lets an attacker who already reads and writes memory get past pointer authentication, the defence built to stop exactly that step. Apple reports attacks against builds released before iOS 15.7.1.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7,
    "vector": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.00487,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "high",
    "kev_added": "2024-01-31",
    "prerequisites": "The attacker must already hold arbitrary memory read and write access."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "macOS Ventura 13.1",
      "iOS 16.2",
      "tvOS 16.2",
      "watchOS 9.2"
    ]
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Update to macOS Ventura 13.1, iOS and iPadOS 16.2, tvOS 16.2 or watchOS 9.2. Devices still below iOS 15.7.1 are the ones Apple saw being attacked.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2022-48618",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2022-48618",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2022-48618",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48618",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213530"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213532"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/HT213535"
    }
  ],
  "published_at": "2024-01-09T18:15:45.120Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "apple",
    "ios",
    "macos",
    "kernel",
    "pointer-authentication",
    "kev"
  ]
}
