A race condition was addressed with improved state handling. This issue is fixed in watchOS 8.6, tvOS 15.5, macOS Monterey 12.4, iOS 15.5 and iPadOS 15.5. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT213258 | vendor advisory |
https://support.apple.com/en-us/HT213253 | vendor advisory |
https://support.apple.com/en-us/HT213254 | vendor advisory |
https://support.apple.com/en-us/HT213257 | vendor advisory |