Deserialization of Untrusted Data in macOS - CVE-2021-31010

 

Deserialization of Untrusted Data in macOS - CVE-2021-31010

Published: February 13, 2023


Vulnerability identifier: #VU72152
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2021-31010
CWE-ID: CWE-502
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
macOS
Software vendor:
Apple Inc.

Description

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to insecure input validation when processing serialized data within the Core Telephony service. A local application can pass specially crafted data to the service and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links