Junglewise Threat Intelligence

CVE-2021-31010: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

CVE-2021-31010 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-08-25

Technologies: Cisco IOS, Apple macOS, Apple iPadOS, Apple watchOS. Vendors: Cisco, Apple.

Executive brief

A deserialization vulnerability in Apple operating systems allows a sandboxed process to circumvent sandbox restrictions. The issue was addressed through improved validation of untrusted data.

Affected products

  • Apple iOS < 12.5.5, < 14.8
  • Apple iPadOS < 14.8
  • Apple macOS Big Sur < 11.6
  • Apple macOS Catalina Security Update 2021-005
  • Apple watchOS < 7.6.2

Timeline

  • 2022-08-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-08-25: disclosed
  • 2021-09-23: patched: Fixed in iOS 12.5.5, iOS 14.8, macOS 11.6, and watchOS 7.6.2
  • exploited: Apple reported awareness of active exploitation at the time of release.

Related threats