CVE-2021-31010
KEVmassDeserialization Sandbox Escape in Apple iOS, iPadOS, macOS, and watchOS
CISA: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
CVE-2021-31010 is a deserialization flaw (CWE-502) in Apple's operating system components that allows a sandboxed process to circumvent the app sandbox restrictions. The CVSS vector (AV:N, no privileges, no user interaction) indicates the vulnerable deserialization path is reachable over the network, and Apple addressed it with improved validation of deserialized data. A successful attacker gains high integrity impact outside the sandbox (CVSS 7.5), a capability that is typically valuable as the second stage of an exploit chain after initial code execution rather than as a standalone bug. Affected users include iPhone and iPad users on iOS/iPadOS prior to 14.8 (or 12.5.5 on older devices), Macs on Catalina or Big Sur prior to the September 2021 updates, and Apple Watch on watchOS prior to 7.6.2. Apple reported the issue may have been actively exploited at the time of release, and CISA confirmed in-the-wild exploitation by adding it to the Known Exploited Vulnerabilities Catalog on 2022-08-25; EPSS currently estimates a 3.7% chance of exploitation in the next 30 days (89th percentile).
What to do: Update iPhones and iPads to iOS/iPadOS 14.8 (or iOS 12.5.5 on devices that cannot run iOS 14), apply macOS Big Sur 11.6 or Security Update 2021-005 Catalina on Macs, and update Apple Watch to watchOS 7.6.2. Treat remediation as a priority per the CISA KEV required action, especially on internet-facing Macs and managed fleets, since a sandbox escape like this is most useful chained with another flaw. No public PoC is known; verify deployed builds via OS version reporting in your device management tooling.
| Apple iPhone OS (iOS) | prior to iOS 14.8; prior to iOS 12.5.5 on older devices |
| Apple iPadOS | prior to iPadOS 14.8 |
| Apple macOS Big Sur | prior to macOS Big Sur 11.6 |
| Apple macOS Catalina | prior to Security Update 2021-005 Catalina |
| Apple watchOS | prior to watchOS 7.6.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
- Affected
- Apple iOS, macOS, watchOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, macos, watchos
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N