CVE-2019-6223: Apple iOS and macOS Group Facetime Vulnerability
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
Other sources
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
— CISA
FaceTime. A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-6223?
CVE-2019-6223 is a vulnerability in Apple iOS and macOS that allows the initiator of a Group FaceTime call to cause the recipient to answer.
How can I be affected by CVE-2019-6223?
You can be affected by CVE-2019-6223 if you are using iOS versions up to 12.1.4, macOS versions up to 10.14.3, or Group FaceTime on Apple devices.
How severe is CVE-2019-6223?
CVE-2019-6223 has a severity rating of 7.5 (high).
How can I fix CVE-2019-6223?
To fix CVE-2019-6223, make sure you have updated your Apple iOS to version 12.1.4 or later, and your macOS to version 10.14.3 Supplemental Update or later.
Where can I find more information about CVE-2019-6223?
You can find more information about CVE-2019-6223 on Apple's official support page: [https://support.apple.com/HT209520](https://support.apple.com/HT209520)