Executive brief
A logic issue in the handling of Group FaceTime calls allowed a remote initiator to cause a recipient's device to answer the call without user interaction. This flaw effectively allowed unauthorized audio/video monitoring of the recipient before they manually accepted the call.
Affected products
- Apple iOS Before 12.1.4
- Apple macOS Mojave Before 10.14.3 Supplemental Update
Timeline
- 2019-03-05: disclosed: NVD Published Date
- 2019-02-07: patched: Apple released iOS 12.1.4 and macOS 10.14.3 Supplemental Update
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry