Another high severity security flaw has hit iOS and macOS devices - so update now

An abstract image of digital security.
(Image credit: Shutterstock) (Image credit: Shutterstock)

A high-severity flaw found in different Mac devices has been observed being abused in the wild, with users advised to apply the patch, which has been available for some time now, as soon as possible. 

The warning was shared by the U.S. Cybersecurity and Infrastructure Agency (CISA) as it added the flaw to its list of Known Exploited Vulnerabilities (KEV), meaning it spotted hackers using it.

The flaw in question is tracked as CVE-2022-48618, and carries a severity score of 7.8. It is described as a bug in the kernel component, affecting iOS, iPadOS, macOS, tvOS, and watchOS devices.

Danger to the government

"An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication," Apple explained the bug in its security advisory. The problem "may have been exploited against versions of iOS released before iOS 15.7.1."

As is almost common practice with these vulnerabilities, Apple fixed it with improved checks. At the moment, we don’t know who the threat actors are, or how they weaponized the vulnerability. It is also unknown if the flaw was used to exfiltrate data, deploy malware, or even ransomware

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA explained, sounding the alarm for government firms who are popular targets among cybercriminals. 

According to The Hacker News, Apple fixed this flaw a long time ago - on December 13, 2022, back when it pushed iOS 16.2, iPadOS 16.2, macOS Ventura 13.1, tvOS 16.2, and watchOS 9.2. However, it only notified the public in early January this year. The same publication also said that Apple already fixed a similar issue, back in July 2022 - CVE-2022-32844 (CVSS score 6.3).

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Apple's new "Share Item Location" feature for AirTags.
Apple security alert - zero-day patched, so update your devices now
Apple Siri
Update your Apple device now: iOS 18.3.2 fixes a flaw that could be exploited by hackers
malware
US government warns federal agencies to patch dangerous Windows kernel bug
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Security
Microsoft reveals more on a potentially major Apple macOS security flaw
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Ray-Ban smart glasses with the Cpperni logo, an LED array, and a MacBook Air with M4 next to ecah other.
ICYMI: the week's 7 biggest tech stories from Twitter's massive outage to iRobot's impressive new Roombas
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight