Race condition in macOS - CVE-2022-46689
Published: December 13, 2022 / Updated: July 27, 2023
Vulnerability identifier: #VU70216
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46689
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a race condition in macOS kernel. A local application can exploit the race and execute arbitrary code with kernel privileges.
Affected software
macOS
watchOS
Apple iOS
iPadOS
tvOS
watchOS
Apple iOS
iPadOS
tvOS
How to mitigate CVE-2022-46689
Install updates from vendor's website.
macOS - addressed in versions 13.1 22C65, 11.7.2 20G1020, 12.6.2 21G320
watchOS - update to 9.2 20S361
Apple iOS - addressed in versions 15.7.2 19H218, 16.2 20C65
iPadOS - addressed in versions 15.7.2 19H218, 16.2 20C65
tvOS - update to 16.2 20K362
watchOS - update to 9.2 20S361
Apple iOS - addressed in versions 15.7.2 19H218, 16.2 20C65
iPadOS - addressed in versions 15.7.2 19H218, 16.2 20C65
tvOS - update to 16.2 20K362
Links to Public Exploits and PoC-codes
- Exploit #9209 - Mandela-Legacy (iOS customization app powered by CVE-2022-46689) (July 27, 2023)
- Exploit #9208 - Mandela-Classic (iOS customization app powered by CVE-2022-46689. No jailbreak required.) (July 27, 2023)
- Exploit #8875 - MacDirtyCow (Example of CVE-2022-46689 aka MacDirtyCow.) (March 1, 2023)
- Exploit #8870 - sw1tch (poc of CVE-2022-46689 written purely in swift) (February 27, 2023)
- Exploit #8851 - Mandela-Rewritten (iOS customization app powered by CVE-2022-46689. No jailbreak required.) (February 20, 2023)
- Exploit #8790 - macOS Dirty Cow Arbitrary File Write Local Privilege Escalation (February 2, 2023)
- Exploit #8714 - FileSwitcherX (CVE-2022-46689) (January 8, 2023)
- Exploit #8711 - DockTransparent (CVE-2022-46689) (January 4, 2023)
- Exploit #8710 - NoHomeBar (CVE-2022-46689) (January 4, 2023)
- Exploit #8707 - NoCameraSound (CVE-2022-46689) (January 3, 2023)
- Exploit #8706 - WDBFontOverwrite (Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.) (January 3, 2023)
- Exploit #8703 - FileManager (File Manager for CVE-2022-46689) (December 29, 2022)
- Exploit #8696 - WDBFontOverwrite (Proof-of-concept app to overwrite fonts on iOS using CVE-2022-46689.) (December 26, 2022)
- Exploit #8677 - MacDirtyCowDemo (Get root on macOS 13.0.1 with CVE-2022-46689 (macOS equivalent of the Dirty Cow bug), using the testcase extracted from Apple's XNU source.) (December 18, 2022)
External References
Related Security Bulletins
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in macOS Monterey
- Multiple vulnerabilities in Apple macOS Big Sur
- Multiple vulnerabilities in Apple iOS 15 and iPadOS 15
- Multiple vulnerabilities in Apple iOS 16 and iPadOS 16
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple watchOS