HomeSecurityCISA: Warns of vulnerability exploitation in Apple products

CISA: Warns of exploiting vulnerability in Apple products

CISA has warned of a kernel vulnerability affecting Apple iPhones, Macs, TVs, and smartwatches. The vulnerability has been patched by the company, but it has begun to be actively used for attacks.

CISA vulnerability

The vulnerability is tracked as CVE-2022-48618 and was discovered by Apple security researchers.

“An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication”the company says. Apple is aware of a report that says this issue may have been exploited in versions of iOS released before iOS 15.7.1.

See also: Android: Exploit released for vulnerability affecting devices from 7 OEMs

This vulnerability allows attackers to bypass Pointer Authentication, a security feature designed to block attacks that attempt to exploit memory corruption bugs. For this reason, CISA recommends that it be patched immediately.

Apple fixed the vulnerability with improved checks on devices running iOS 16.2 or later, iPadOS 16.2 or later, macOS Ventura or later, tvOS 16.2 or later, and watchOS 9.2 or later.

Affected devices include::

  • iPhone 8 and later, iPad Pro (all models), iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later
  • Macs running macOS Ventura
  • Apple TV 4K, Apple TV 4K (2nd generation and later), and Apple TV HD
  • and Apple Watch Series 4 and later

See also: Ivanti warns of two new Connect Secure vulnerabilities

iPhone Mac Apple vulnerability

Federal agencies are being asked to patch the vulnerability on their devices by February 21. Alternatively, they will have to stop using the vulnerable devices.

Apple has not yet provided details about the exploit for the CVE-2022-48618 vulnerability, but CISA has added it to the List of Known Exploitable Vulnerabilities.

CISA's KEV list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

Overall, CISA is a great help in protecting and threats cybersecurity. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.

See also: Vulnerability in glibc allows root access on Linux distributions

It provides information and tools to help organizations protect their networks from cyberattacks and deal with any attacks that may occur.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In addition, it informs the public about any vulnerabilities in widely used systems and applications. Overall, CISA's role is vital to protecting the digital infrastructure of the United States and other regions.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS