CVE-2021-31010 Information

Description

A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina iOS 12.5.5 iOS 14.8 and iPadOS 14.8 macOS Big Sur 11.6 watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Reference

https://support.apple.com/en-us/HT212824 https://support.apple.com/en-us/HT212806 https://support.apple.com/en-us/HT212807 https://support.apple.com/en-us/HT212804 https://support.apple.com/en-us/HT212805

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

7.5

Share on: