Executive brief
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption vulnerability. An attacker with arbitrary read and write capabilities can exploit this race condition to bypass Pointer Authentication (PAC).
Affected products
- Apple iOS < 16.2
- Apple iPadOS < 16.2
- Apple macOS Ventura 13.0 to < 13.1
- Apple tvOS < 16.2
- Apple watchOS < 9.2
Timeline
- 2024-01-31: disclosed: NVD publication date
- 2024-01-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-31: exploited: Apple reported awareness of exploitation against iOS versions prior to 15.7.1
- 2022-12-13: patched: Fixed in macOS 13.1, watchOS 9.2, iOS/iPadOS/tvOS 16.2