Skip to content
COOEY

EXPOSURES › CVE-2019-6223

CVE-2019-6223

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-6223 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildauth-bypass

An unspecified vulnerability in Apple's Group FaceTime allowed call initiators to force recipients' devices to answer calls without user interaction.

This vulnerability bypassed user consent for answering calls, potentially enabling unauthorized access or eavesdropping. DIB organizations must ensure all endpoints are patched and that users are trained to recognize unexpected call behaviors, as this represents a significant bypass of authentication controls.

Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed a bypass of user authentication controls, representing a significant avoidable risk despite Apple's eventual patch.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.

SENTIMENT · TRUSTED SOURCES
synthesis neutral -0.20
No direct press coverage or authoritative commentary found in the provided sources; only CVE database listings and unrelated articles.
cooey ↗ neutral +0.00
Neutral CVE database entry with no commentary on vendor response.
"Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction."
www.cvefind.com ↗ neutral +0.00
Neutral CVE database entry with no commentary on vendor response.
"CVE 2026"
app.opencve.io ↗ neutral +0.00
Neutral CVE database entry with no commentary on vendor response.
"CVEs and Security Vulnerabilities - OpenCVE"
www.tenable.com ↗ neutral +0.00
Neutral CVE database entry with no commentary on vendor response.
"CVE-2026-62223 | Tenable®"
SentinelOne ↗ neutral +0.00
Neutral CVE database entry with no commentary on vendor response.
"Vulnerability Database | SentinelOne"
Neutral CVE database entry with no commentary on vendor response.
"PSIRT | FortiGuard Labs"
finance.yahoo.com ↗ neutral +0.00
Neutral Unrelated article about a different Apple security incident.
"Apple says former employee exploited 'rare' bug to download confidential files after leaving for OpenAI"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.