CVE-2019-6223 is a logic issue affecting Apple's iOS and macOS Group FaceTime, allowing an attacker to force a recipient to answer a call. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low attack complexity, and high confidentiality impact, as it could enable unauthorized eavesdropping. It is listed on the CISA KEV catalog, indicating active exploitation, despite no public exploit code being readily available in common databases like Metasploit or ExploitDB. The vulnerability garnered significant media attention and community discussion, highlighting its real-world impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.4CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.14.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.