VulnerabilityAnalyzed
CVE-2019-6223
Apple iOS and macOS Group Facetime Vulnerability
KEVHIGH 7.5EPSS 2.63%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Affected
- apple/iphone os · apple/mac os x
- Source
- product-security@apple.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-6223
References
- https://support.apple.com/HT209520Release Notes, Vendor Advisory
- https://support.apple.com/HT209521Release Notes, Vendor Advisory
- https://support.apple.com/HT209520Release Notes, Vendor Advisory
- https://support.apple.com/HT209521Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-6223US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.