cbcvebase.
CVE-2019-6223
published 2019-03-05

CVE-2019-6223: A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS…

PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.63%
83.8th percentile
A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be able to cause the recipient to answer.

Affected

6 ranges
VendorProductVersion rangeFixed in
appleios
appleios>= unspecified < iOS 12.1.3iOS 12.1.3
appleiphone_os< 12.1.412.1.4
applemac_os_x< 10.14.310.14.3
applemacos>= unspecified < macOS Mojave 10.14.3macOS Mojave 10.14.3
applemacos_mojave_10.14.3_supplemental_update

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for Group FaceTime calls being answered without user interaction or consent, which may indicate exploitation of the logic flaw in call state management.
  • Focus detection on FaceTime component behavior on unpatched iOS versions prior to 12.1.4 and macOS Mojave versions prior to 10.14.3 Supplemental Update.
  • Flag devices where FaceTime audio/video sessions are established without explicit user acceptance — indicative of the improper state management being exploited.
  • ·No specific exploit code, network indicators, hashes, or signatures are publicly documented for this vulnerability. Detection is limited to behavioral and version-based indicators.
  • ·The vulnerability is a logic/state management flaw in the FaceTime component, not a memory corruption or code injection issue, making network-level detection signatures difficult to craft.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.