Overview
- Description
- A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
- Source
- product-security@apple.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Known exploits
Data from CISA
- Vulnerability name
- Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
- Exploit added on
- Aug 25, 2022
- Exploit action due
- Sep 15, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-502
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FCD67B72-0B1D-46A8-A149-8149ED749FEC", "versionEndExcluding": "14.8" }, { "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5527D436-59EA-4ACB-8828-1D62BDEBCAAD", "versionEndExcluding": "12.5.5", "versionStartIncluding": "12.0" }, { "criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C500EA50-9DE1-42F7-8C6D-D0409C2EE734", "versionEndExcluding": "14.8", "versionStartIncluding": "14.0" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DB8A73F8-3074-4B32-B9F6-343B6B1988C5", "versionEndExcluding": "10.15.7", "versionStartIncluding": "10.15" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A654B8A2-FC30-4171-B0BB-366CD7ED4B6A" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F12CC8B5-C1EB-419E-8496-B9A3864656AD" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F1F4BF7F-90D4-4668-B4E6-B06F4070F448" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-005:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FD7176C-F4D1-43A7-9E49-BA92CA0D9980" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-007:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2703DE0B-8A9E-4A9D-9AE8-028E22BF47CA" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0F441A43-1669-478D-9EC8-E96882DE4F9F" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D425C653-37A2-448C-BF2F-B684ADB08A26" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A54D63B7-B92B-47C3-B1C5-9892E5873A98" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "012052B5-9AA7-4FD3-9C80-5F615330039D" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "50F21A3C-0AC3-48C5-A4F8-5A7B478875B4" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8E974DC6-F7D9-4389-9AF9-863F6E419CE6" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "156A6382-2BD3-4882-90B2-8E7CF6659E17" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20A2FDB2-6712-406A-9896-C0B44508B07D" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-003:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49F537A0-DC42-4176-B22F-C80D179DD99D" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-004:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E463183-7E29-464F-B459-F3E1D62501FC" }, { "criteria": "cpe:2.3:o:apple:mac_os_x:10.15.7:supplemental_update:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1C795B9-E58D-467C-83A8-2D45C792292F" }, { "criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C416CDE-C6B5-4F68-8095-A4657F64C370", "versionEndExcluding": "11.6", "versionStartIncluding": "11.0" }, { "criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3232C3B6-D79F-4FDB-9621-4E314798AD7D", "versionEndExcluding": "7.6.2" } ], "operator": "OR" } ] } ]