CVE-2021-31010: Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
Core Telephony. A deserialization issue was addressed through improved validation.
Other sources
In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.
— CISA
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 11.6 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 12.5.5 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 14.8 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 14.8 - Upgrade
Upgrade
macOS Big Surto a version that resolves this vulnerability.Fixed in 11.6 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 7.6.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Security Update 2021-005 Catalina
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30811
- CVE-2021-30838
- CVE-2021-30834
- CVE-2021-30928
- CVE-2021-30860
- CVE-2021-31010
- CVE-2021-30827
- CVE-2021-30828
- CVE-2021-30829
- CVE-2021-22925
- CVE-2021-30832
- CVE-2021-30841
- CVE-2021-30842
- CVE-2021-30843
- CVE-2021-30853
- CVE-2021-30933
- CVE-2021-30835
- CVE-2021-30847
- CVE-2021-30830
- CVE-2021-30865
- CVE-2021-30857
- CVE-2021-30859
- CVE-2021-30864
- CVE-2013-0340
- CVE-2021-30813
- CVE-2021-30819
- CVE-2021-30855
- CVE-2021-30925
- CVE-2021-30850
- CVE-2021-30845
- CVE-2021-30844
- CVE-2021-30858
- CVE-2021-30783
- CVE-2020-29622
- CVE-2021-30713
- CVE-2021-30869
- CVE-2021-30820
- CVE-2021-30905
- CVE-2021-30852
- CVE-2021-30826
- CVE-2021-30818
- CVE-2021-30823
- CVE-2021-30836
- CVE-2021-30848
- CVE-2021-30849
- CVE-2021-30846
Frequently Asked Questions
What is CVE-2021-31010?
CVE-2021-31010 is a vulnerability in Apple iOS, macOS, and watchOS that allows a sandboxed process to bypass sandbox restrictions.
How does CVE-2021-31010 affect Apple devices?
CVE-2021-31010 affects Apple devices running iOS, macOS, and watchOS.
What is the severity of CVE-2021-31010?
The severity of CVE-2021-31010 is not specified in the provided information.
How can I fix CVE-2021-31010?
To fix CVE-2021-31010, update your Apple devices to the recommended versions: iOS 12.5.5, macOS Big Sur 11.6, or watchOS 7.6.2.
Where can I find more information about CVE-2021-31010?
You can find more information about CVE-2021-31010 on the official Apple support page: [CVE-2021-31010](https://support.apple.com/en-us/HT212804)