CVE-2019-6223 KEV
7.5
HIGH · CVSS 3.1 · EPSS 2.6% (pctl 85)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 2.63% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | none known |
| Published | 2019-03-05 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apple iOS and macOS Group Facetime Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Apple / iOS and macOS |
| Ransomware use | none reported |
Affected (2)
| Vendor | Product |
|---|---|
| apple | iphone os |
| apple | mac os x |
References
→ the Explorer · watch your stack · NVD