ZeroHour

CVE-2021-31010

KEVmass

Deserialization Sandbox Escape in Apple iOS, iPadOS, macOS, and watchOS

CISA: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

CVSS 3.1
7.5 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2021-31010 is a deserialization flaw (CWE-502) in Apple's operating system components that allows a sandboxed process to circumvent the app sandbox restrictions. The CVSS vector (AV:N, no privileges, no user interaction) indicates the vulnerable deserialization path is reachable over the network, and Apple addressed it with improved validation of deserialized data. A successful attacker gains high integrity impact outside the sandbox (CVSS 7.5), a capability that is typically valuable as the second stage of an exploit chain after initial code execution rather than as a standalone bug. Affected users include iPhone and iPad users on iOS/iPadOS prior to 14.8 (or 12.5.5 on older devices), Macs on Catalina or Big Sur prior to the September 2021 updates, and Apple Watch on watchOS prior to 7.6.2. Apple reported the issue may have been actively exploited at the time of release, and CISA confirmed in-the-wild exploitation by adding it to the Known Exploited Vulnerabilities Catalog on 2022-08-25; EPSS currently estimates a 3.7% chance of exploitation in the next 30 days (89th percentile).

What to do: Update iPhones and iPads to iOS/iPadOS 14.8 (or iOS 12.5.5 on devices that cannot run iOS 14), apply macOS Big Sur 11.6 or Security Update 2021-005 Catalina on Macs, and update Apple Watch to watchOS 7.6.2. Treat remediation as a priority per the CISA KEV required action, especially on internet-facing Macs and managed fleets, since a sandbox escape like this is most useful chained with another flaw. No public PoC is known; verify deployed builds via OS version reporting in your device management tooling.

Affected
Apple iPhone OS (iOS)prior to iOS 14.8; prior to iOS 12.5.5 on older devices
Apple iPadOSprior to iPadOS 14.8
Apple macOS Big Surprior to macOS Big Sur 11.6
Apple macOS Catalinaprior to Security Update 2021-005 Catalina
Apple watchOSprior to watchOS 7.6.2
Estimated exposure
mass≈1 billion+ Apple devices (hundreds of millions of iPhones/iPads on the affected iOS/iPadOS releases, plus Macs and Apple Watches on affected builds) — The advisory fixes spanned Apple's then-current OS fleet in September 2021, when Apple's active device install base exceeded one billion and the affected versions (iOS 14, macOS Catalina/Big Sur, watchOS 7) covered the large majority of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..

CISA Known Exploited Vulnerability
Affected
Apple iOS, macOS, watchOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x, macos, watchos
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news