Deserialization of Untrusted Data in macOS - CVE-2021-31010
Published: February 13, 2023
macOS
Apple Inc.
Description
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to insecure input validation when processing serialized data within the Core Telephony service. A local application can pass specially crafted data to the service and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild.