← Vulnerability feed

Vulnerability record · CVE-2021-31010 · published 24 August 2021

CVE-2021-31010: Apple iOS, iPadOS, macOS and watchOS sandbox bypass via deserialization

Apple · Ipados

A deserialization flaw in Apple operating systems was fixed through improved validation. A sandboxed process could bypass sandbox restrictions, and Apple stated it was aware of a report that the issue may have been actively exploited at release. The record does not name the specific component or the affected code path.

7.5 CVSS 3.1 High CISA KEV since 25 Aug 2022 EPSS 3.7% · top 10.7% CWE-502 · Deserialization of untrusted data
7.5CVSS 3.1 base score, v2 5.0
3.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
5Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with confirmed in-the-wild exploitation reported by Apple, but exploitation requires an existing sandboxed foothold and the record lacks component-level detail.

What it is

A deserialization flaw in Apple operating systems was fixed through improved validation. A sandboxed process could bypass sandbox restrictions, and Apple stated it was aware of a report that the issue may have been actively exploited at release. The record does not name the specific component or the affected code path.

Impact

An attacker who already has code running inside a sandbox can escape those restrictions and reach resources or data the sandbox was meant to protect. The CVSS vector rates integrity impact as high with no confidentiality or availability impact.

Attack surface

The vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), but the description frames the flaw as a sandboxed process circumventing its own sandbox, so practical exploitation requires a foothold in a sandboxed process rather than direct remote access. No further detail on the entry point is given.

Exploitation

Apple stated it was aware of a report that the issue may have been actively exploited at release, and CISA added it to the KEV catalog on 2022-08-25. EPSS 30-day probability is 0.03673 (89th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor updates: Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2.
  • Inventory Apple devices and confirm none remain on versions older than those listed.
  • Treat devices that cannot be updated as high risk and restrict what runs on them.
  • Review sandbox escape paths in any in-house code that deserializes untrusted data, since the root cause is CWE-502.
  • Track KEV remediation deadlines for any remaining unpatched endpoints.

Detection

  • Monitor for processes escaping expected sandbox confinement, such as sandboxed apps spawning unexpected child processes or touching files outside their container.
  • Alert on anomalous inter-process or network activity originating from sandboxed applications.
  • Correlate endpoint telemetry with known post-exploitation behavior on Apple devices running unpatched versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-31010 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-31010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 22%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed9.8CVE-2026-65400Apple macOS Screen Sharing authentication bypassAn improper authentication flaw in Apple macOS Screen Sharing allows a network attacker to authenticate without valid credentials. Apple fixed it via…KEVEPSS 1.2%analysed9.8CVE-2025-31200Apple OS media parsing memory corruption allows code executionA memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 19%analysed9.8CVE-2025-31201Apple OS Pointer Authentication bypass via arbitrary read/writeApple removed vulnerable code that allowed an attacker holding arbitrary read and write capability to bypass Pointer Authentication across iOS, iPadO…KEVEPSS 14%analysed9.8CVE-2022-22587Apple iOS, iPadOS and macOS kernel memory corruption via out-of-bounds writeAn out-of-bounds write (CWE-787) in Apple iOS, iPadOS and macOS is caused by insufficient input validation and can corrupt memory. Apple states it is…KEVEPSS 12%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2021-31010), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.