CVE-2021-31010
CVE Published | 2021-08-24 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | apple |
Related Product(s) | mac_os_x, ipados, iphone_os, macos, watchos |
Exploitation Reported (CISA KEV) | 2022-08-25 |
CVSS 3 Base Score | 7.5 (HIGH) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph