Cyber Resilience

CVE-2019-6223

Apple Iphone Os ≤ 12.1.4

CISA KEVActive ExploitationEUVD Exploited
Published
05 March 2019
Modified
23 October 2025
KEV Added
03 November 2021
Patch / advisory
CVSS Score v3.1 7.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.026 84th percentile
Risk Priority 84 floored blend · peak EPSS

Summary

CVE-2019-6223 is a high-severity an unspecified weakness vulnerability in Apple Iphone Os. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 16% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A logic issue in the handling of Group FaceTime calls, caused by inadequate state management, affected Apple iOS and macOS devices prior to the listed updates. The vulnerability resided in the FaceTime component and carried a CVSS 3.1 base score of 7.5, reflecting network-accessible exploitation with no required privileges or user interaction and a high impact on confidentiality.

An unauthenticated remote attacker acting as the initiator of a Group FaceTime call could exploit the flaw to force the recipient’s device to answer automatically, thereby gaining unauthorized audio or video access without the recipient’s knowledge or consent.

Apple addressed the issue through improved state management in iOS 12.1.4 and the macOS Mojave 10.14.3 Supplemental Update, as documented in security advisories HT209520 and HT209521. The vulnerability is also catalogued by CISA as one known to have been exploited in the wild.

EU & UK References

Vulnerability Data

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.1.4, macOS Mojave 10.14.3 Supplemental Update. The initiator of a Group FaceTime call may be…

more

able to cause the recipient to answer.

CWE(s)
KEV Date Added
03 November 2021

Related Threats

CVEs Like This One

CVE-2019-7286Same product: Apple Iphone Osboth on KEV
CVE-2014-4404Same product: Apple Iphone Osboth on KEV
CVE-2020-9934Same product: Apple Iphone Osboth on KEV
CVE-2021-30761Same product: Apple Iphone Osboth on KEV
CVE-2021-30762Same product: Apple Iphone Osboth on KEV
CVE-2016-4655Same product: Apple Iphone Osboth on KEV
CVE-2021-30666Same product: Apple Iphone Osboth on KEV
CVE-2019-8526Same product: Apple Mac Os Xboth on KEV
CVE-2019-8605Same product: Apple Iphone Osboth on KEV
CVE-2016-4656Same product: Apple Iphone Osboth on KEV

Affected Assets

apple
iphone os
≤ 12.1.4
apple
mac os x
≤ 10.14.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References