VulnerabilityModified
CVE-2019-8856
An API issue existed in the handling of outgoing phone calls initiated with Siri.
LOW 3.3EPSS 0.68%
Does this matter?
Lower severity and a low EPSS score (0.68%). Track it; it rarely justifies an emergency change on its own.
Description
An API issue existed in the handling of outgoing phone calls initiated with Siri. This issue was addressed with improved state handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra. Calls made using Siri may be initiated using the wrong cellular plan on devices with two active plans.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- EPSS
- 0.68% probability · 51th percentile
- CISA KEV
- Not listed
- Affected
- apple/ipados · apple/iphone os · apple/mac os x · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210788Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210789Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210785Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210788Release Notes, Vendor Advisory
- https://support.apple.com/en-us/HT210789Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.