CVE-2021-31010
Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 7.5
- EPSS
- 3.67% 백분위 88.3% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.09.15
- 공개일
- 2021.08.25
CISA KEV에 등록된 실제 악용 확인 취약점
A deserialization issue was addressed through improved validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 12.5.5, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. A sandboxed process may be able to circumvent sandbox restrictions. Apple was aware of a report that this issue may have been actively exploited at the time of release..
공급사 Apple
제품 iOS, macOS, watchOS
영향 버전 unspecified, < 14.8, >= 12.0 < 12.5.5, >= 14.0 < 14.8, >= 10.15 < 10.15.7, 10.15.7, >= 11.0 < 11.6, < 7.6.2
수정 버전 14.8, 12.5.5, 10.15.7, 11.6, 7.6.2
Apply updates per vendor instructions.
조치 기한: 2022.09.15CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE CWE-20, CWE-502
KEV 등록일 2022.08.25
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://support.apple.com/en-us/HT212804, https://support.apple.com/en-us/HT212805, https://support.apple.com/en-us/HT212806, https://support.apple.com/en-us/HT212807, https://support.apple.com/en-us/HT212824; https://nvd.nist.gov/vuln/detail/CVE-2021-31010
EPSS 데이터 기준일 2026.06.27