ZeroHour

CVE-2019-6223

KEVmass

Apple iOS/macOS Group FaceTime Auto-Answer Flaw Enables Silent Eavesdropping

CISA: Apple iOS and macOS Group Facetime Vulnerability

CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
KEV added
AI analysis

A logic flaw in the handling of Group FaceTime calls on Apple iOS and macOS let the initiator of a Group FaceTime call cause the recipient's device to answer automatically, without the user accepting. An attacker who called a victim's FaceTime identity could thereby listen in on the recipient's surroundings before the call was accepted - a silent eavesdropping condition consistent with the CVSS confidentiality-high rating. Users of iPhones and iPads running iOS releases with Group FaceTime prior to 12.1.4, and Macs running macOS Mojave prior to the 10.14.3 Supplemental Update, were affected. Apple shipped fixes in iOS 12.1.4 and the macOS Mojave 10.14.3 Supplemental Update. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation, while EPSS puts near-term exploitation probability at about 2.6% (85th percentile) and no public proof-of-concept code is known.

What to do: Upgrade iPhones and iPads to iOS 12.1.4 or later and Macs to macOS Mojave 10.14.3 Supplemental Update or later. As an interim mitigation, disable FaceTime or avoid placing/accepting Group FaceTime calls until patched, and verify managed fleets have the updates applied per the CISA KEV required action.

Affected
apple iphone os (iOS on iPhone/iPad)iOS releases with Group FaceTime prior to 12.1.4 (fixed in iOS 12.1.4)
apple mac os x (macOS Mojave)macOS Mojave prior to 10.14.3 Supplemental Update (fixed in 10.14.3 Supplemental Update)
Estimated exposure
masshundreds of millions of consumer devices (Apple's active iPhone/Mac install base, with the affected Group FaceTime-era iOS and macOS Mojave releases widely… — Apple's active install base runs to many hundreds of millions of iPhones and tens of millions of Macs, and the affected releases were broadly rolled out to FaceTime-using consumers in early 2019, making device-level exposure plausibly in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

CISA Known Exploited Vulnerability
Affected
Apple iOS and macOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
iphone os, mac os x
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news