CVE-2019-6223

Confirmed PUBLISHED

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS...

Vendor: Apple Product: iOS, macOS
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High EPSS 2.6%

At a Glance

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

macos cisa ios
CVE Published
Mar 05, 2019
Exploitation Reported
Nov 03, 2021
CVSS
7.5 High
EPSS
2.6%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Apple
iOS

unspecified to < iOS 12.1.3

Affected
Apple
macOS

unspecified to < macOS Mojave 10.14.3

Affected

CVE References