Junglewise Threat Intelligence

CVE-2019-6223: Apple iOS and macOS Group Facetime Vulnerability

CVE-2019-6223 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS. Vendors: Apple.

Executive brief

A logic issue in the handling of Group FaceTime calls allowed a remote initiator to cause a recipient's device to answer the call without user interaction. This flaw effectively allowed unauthorized audio/video monitoring of the recipient before they manually accepted the call.

Affected products

  • Apple iOS Before 12.1.4
  • Apple macOS Mojave Before 10.14.3 Supplemental Update

Timeline

  • 2019-03-05: disclosed: NVD Published Date
  • 2019-02-07: patched: Apple released iOS 12.1.4 and macOS 10.14.3 Supplemental Update
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry

Related threats