Executive brief
A deserialization vulnerability in Apple operating systems allows a sandboxed process to circumvent sandbox restrictions. The issue was addressed through improved validation of untrusted data.
Affected products
- Apple iOS < 12.5.5, < 14.8
- Apple iPadOS < 14.8
- Apple macOS Big Sur < 11.6
- Apple macOS Catalina Security Update 2021-005
- Apple watchOS < 7.6.2
Timeline
- 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-25: disclosed
- 2021-09-23: patched: Fixed in iOS 12.5.5, iOS 14.8, macOS 11.6, and watchOS 7.6.2
- exploited: Apple reported awareness of active exploitation at the time of release.