CVE-2021-31010
published 2021-08-24CVE-2021-31010: A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS…
PriorityP279high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-09-15
Exploited in the wild
EPSS
3.67%
88.5th percentile
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | — | — |
| apple | ios_14.8_and_ipados | — | — |
| apple | ipados | < 14.8 | 14.8 |
| apple | iphone_os | >= 12.0 < 12.5.5 | 12.5.5 |
| apple | iphone_os | >= 14.0 < 14.8 | 14.8 |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6 | 11.6 |
| apple | macos | >= unspecified < 11.6 | 11.6 |
| apple | macos | >= unspecified < 2021 | 2021 |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-005_catalina | — | — |
| apple | watchos | < 7.6.2 | 7.6.2 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < 7.6 | 7.6 |
| apple | watchos | >= unspecified < 14.8 | 14.8 |
| apple | watchos | >= unspecified < 12.5 | 12.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable component is Core Telephony on Apple platforms; monitor for sandboxed processes attempting to circumvent sandbox restrictions via deserialization in Core Telephony ↗
- →CVE-2021-31010 affects Core Telephony deserialization; prioritize detection on unpatched iOS < 14.8, iOS < 12.5.5, macOS Catalina without Security Update 2021-005, macOS Big Sur < 11.6, and watchOS < 7.6.2 ↗
- →CISA confirmed active exploitation; treat any anomalous sandbox escape behavior on Apple devices involving Core Telephony as high-priority incident ↗
- ·No technical details, PoC, hashes, network indicators, or specific exploit artifacts were disclosed in any source; all sources are vendor advisories and CISA catalog entries only ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
cisa·2022-08-25·CVSS 7.5
CVE-2021-31010 [HIGH] CWE-20 Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
Vulnerability: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
Affected: Apple iOS, macOS, watchOS
In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
Required Action: Apply updates per vendor instructions.
Notes: https://support.apple.com/en-us/HT212804, https://support.apple.com/en-us/HT212805, https://support.apple.com/en-us/HT212806, https://support.apple.com/en-us/HT212807, https://support.apple.com/en-us/HT212824; https://nvd.nist.gov/vuln/detail/CVE-2021-31010
Remediation Due Date: 2022-09-15
Apple
CVE-2021-31010: iOS 12.5.5
vendor_apple·2021-09-23·CVSS 7.5
CVE-2021-31010 [HIGH] CVE-2021-31010: iOS 12.5.5
Apple Security Update: About the security content of iOS 12.5.5
Product: iOS
Version: 12.5.5
CVE: CVE-2021-31010
Component: Core Telephony
Impact: A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.
Description: A deserialization issue was addressed through improved validation.
Apple
CVE-2021-31010: iOS 14.8 and iPadOS 14.8
vendor_apple·2021-09-13·CVSS 7.5
CVE-2021-31010 [HIGH] CVE-2021-31010: iOS 14.8 and iPadOS 14.8
Apple Security Update: About the security content of iOS 14.8 and iPadOS 14.8
Product: iOS 14.8 and iPadOS
Version: 14.8
CVE: CVE-2021-31010
Component: Core Telephony
Impact: A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.
Description: A deserialization issue was addressed through improved validation.
Apple
CVE-2021-31010: Security Update 2021-005 Catalina
vendor_apple·2021-09-13·CVSS 7.5
CVE-2021-31010 [HIGH] CVE-2021-31010: Security Update 2021-005 Catalina
Apple Security Update: About the security content of Security Update 2021-005 Catalina
Product: Security Update 2021-005 Catalina
CVE: CVE-2021-31010
Component: Core Telephony
Impact: A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.
Description: A deserialization issue was addressed through improved validation.
Apple
CVE-2021-31010: watchOS 7.6.2
vendor_apple·2021-09-13·CVSS 7.5
CVE-2021-31010 [HIGH] CVE-2021-31010: watchOS 7.6.2
Apple Security Update: About the security content of watchOS 7.6.2
Product: watchOS
Version: 7.6.2
CVE: CVE-2021-31010
Component: Core Telephony
Impact: A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.
Description: A deserialization issue was addressed through improved validation.
Apple
CVE-2021-31010: macOS Big Sur 11.6
vendor_apple·2021-09-13·CVSS 7.5
CVE-2021-31010 [HIGH] CVE-2021-31010: macOS Big Sur 11.6
Apple Security Update: About the security content of macOS Big Sur 11.6
Product: macOS Big Sur
Version: 11.6
CVE: CVE-2021-31010
Component: Core Telephony
Impact: A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release.
Description: A deserialization issue was addressed through improved validation.
VulnCheck
Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
vulncheck·2021·CVSS 7.5
CVE-2021-31010 [HIGH] CWE-20 Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
Affected: Apple iOS, macOS, watchOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/en-us/103147; https://support.apple.com/en-us/103148; https://support.apple.com/kb/HT212806; https://support.apple.com/kb/HT212807; https://support.apple.com/en-us/103157; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buying_Spying_-_Insights_into_Commercial_Surveillance_Vendors
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212805https://support.apple.com/en-us/HT212806https://support.apple.com/en-us/HT212807https://support.apple.com/en-us/HT212824https://support.apple.com/en-us/HT212804https://support.apple.com/en-us/HT212805https://support.apple.com/en-us/HT212806https://support.apple.com/en-us/HT212807https://support.apple.com/en-us/HT212824https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31010
2021-08-24
Published
2022-08-25
Added to CISA KEV
Exploited in the wild