CVE-2019-6223
KEVmassApple iOS/macOS Group FaceTime Auto-Answer Flaw Enables Silent Eavesdropping
CISA: Apple iOS and macOS Group Facetime Vulnerability
A logic flaw in the handling of Group FaceTime calls on Apple iOS and macOS let the initiator of a Group FaceTime call cause the recipient's device to answer automatically, without the user accepting. An attacker who called a victim's FaceTime identity could thereby listen in on the recipient's surroundings before the call was accepted - a silent eavesdropping condition consistent with the CVSS confidentiality-high rating. Users of iPhones and iPads running iOS releases with Group FaceTime prior to 12.1.4, and Macs running macOS Mojave prior to the 10.14.3 Supplemental Update, were affected. Apple shipped fixes in iOS 12.1.4 and the macOS Mojave 10.14.3 Supplemental Update. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming in-the-wild exploitation, while EPSS puts near-term exploitation probability at about 2.6% (85th percentile) and no public proof-of-concept code is known.
What to do: Upgrade iPhones and iPads to iOS 12.1.4 or later and Macs to macOS Mojave 10.14.3 Supplemental Update or later. As an interim mitigation, disable FaceTime or avoid placing/accepting Group FaceTime calls until patched, and verify managed fleets have the updates applied per the CISA KEV required action.
| apple iphone os (iOS on iPhone/iPad) | iOS releases with Group FaceTime prior to 12.1.4 (fixed in iOS 12.1.4) |
| apple mac os x (macOS Mojave) | macOS Mojave prior to 10.14.3 Supplemental Update (fixed in 10.14.3 Supplemental Update) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
- Affected
- Apple iOS and macOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- iphone os, mac os x
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N