Vulnerability record · CVE-2021-31010 · published 24 August 2021
CVE-2021-31010: Apple iOS, iPadOS, macOS and watchOS sandbox bypass via deserialization
Apple · Ipados
A deserialization flaw in Apple operating systems was fixed through improved validation. A sandboxed process could bypass sandbox restrictions, and Apple stated it was aware of a report that the issue may have been actively exploited at release. The record does not name the specific component or the affected code path.
Description
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation reported by Apple, but exploitation requires an existing sandboxed foothold and the record lacks component-level detail.
What it is
A deserialization flaw in Apple operating systems was fixed through improved validation. A sandboxed process could bypass sandbox restrictions, and Apple stated it was aware of a report that the issue may have been actively exploited at release. The record does not name the specific component or the affected code path.
Impact
An attacker who already has code running inside a sandbox can escape those restrictions and reach resources or data the sandbox was meant to protect. The CVSS vector rates integrity impact as high with no confidentiality or availability impact.
Attack surface
The vector is network-reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), but the description frames the flaw as a sandboxed process circumventing its own sandbox, so practical exploitation requires a foothold in a sandboxed process rather than direct remote access. No further detail on the entry point is given.
Exploitation
Apple stated it was aware of a report that the issue may have been actively exploited at release, and CISA added it to the KEV catalog on 2022-08-25. EPSS 30-day probability is 0.03673 (89th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor updates: Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2.
- Inventory Apple devices and confirm none remain on versions older than those listed.
- Treat devices that cannot be updated as high risk and restrict what runs on them.
- Review sandbox escape paths in any in-house code that deserializes untrusted data, since the root cause is CWE-502.
- Track KEV remediation deadlines for any remaining unpatched endpoints.
Detection
- Monitor for processes escaping expected sandbox confinement, such as sandboxed apps spawning unexpected child processes or touching files outside their container.
- Alert on anomalous inter-process or network activity originating from sandboxed applications.
- Correlate endpoint telemetry with known post-exploitation behavior on Apple devices running unpatched versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-31010 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/en-us/HT212804 | Vendor Advisory |
| https://support.apple.com/en-us/HT212805 | Vendor Advisory |
| https://support.apple.com/en-us/HT212806 | Vendor Advisory |
| https://support.apple.com/en-us/HT212807 | Vendor Advisory |
| https://support.apple.com/en-us/HT212824 | Vendor Advisory |
| https://support.apple.com/en-us/HT212804 | Vendor Advisory |
| https://support.apple.com/en-us/HT212805 | Vendor Advisory |
| https://support.apple.com/en-us/HT212806 | Vendor Advisory |
| https://support.apple.com/en-us/HT212807 | Vendor Advisory |
| https://support.apple.com/en-us/HT212824 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-31010 | US Government Resource |
Track CVE-2021-31010 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-31010), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.