peter bassill · operator
$ cve CVE-2019-6223 JSON

CVE-2019-6223 KEV

7.5
HIGH · CVSS 3.1 · EPSS 2.6% (pctl 85)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS2.63% — more likely to be exploited than 85% of all CVEs
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2019-03-05
Last modified2026-06-17

CISA KEV

NameApple iOS and macOS Group Facetime Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productApple / iOS and macOS
Ransomware usenone reported

Affected (2)

VendorProduct
appleiphone os
applemac os x

References

→ the Explorer  ·  watch your stack  ·  NVD