Vulnerability Name: | CVE-2019-6223 (CCN-156174) | ||||||||||||
Assigned: | 2019-01-28 | ||||||||||||
Published: | 2019-01-28 | ||||||||||||
Updated: | 2020-08-24 | ||||||||||||
Summary: | A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-6223 Source: CCN Type: 9toMac Web site Major iPhone FaceTime bug lets you hear the audio of the person you are calling before they pick up Source: XF Type: UNKNOWN appleios-facetime-cve20196223-info-disc(156174) Source: CCN Type: Apple security document HT209521 About the security content of iOS 12.1.4 Source: CCN Type: Apple security document HT209520 About the security content of macOS Mojave 10.14.3 Supplemental Update Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT209520 Source: CONFIRM Type: Vendor Advisory https://support.apple.com/HT209521 Source: CCN Type: Apple Web site iOS Source: CCN Type: BuzzFeed News Web site A FaceTime Bug Allows You To Access Someone's iPhone Camera And Microphone Before They Pick Up Source: CCN Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY KNOWN EXPLOITED VULNERABILITIES CATALOG | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |