SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-6223

Apple iOS and macOS Group Facetime Vulnerability

KEVHIGH 7.5EPSS 2.63%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.63% probability · 85th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022
Affected
apple/iphone os · apple/mac os x
Source
product-security@apple.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-6223

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.