EXPOSURES › CVE-2019-6223
CVE-2019-6223
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unspecified vulnerability in Apple's Group FaceTime allowed call initiators to force recipients' devices to answer calls without user interaction.
This vulnerability bypassed user consent for answering calls, potentially enabling unauthorized access or eavesdropping. DIB organizations must ensure all endpoints are patched and that users are trained to recognize unexpected call behaviors, as this represents a significant bypass of authentication controls.
Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed a bypass of user authentication controls, representing a significant avoidable risk despite Apple's eventual patch.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction.
"Apple iOS and macOS Group FaceTime contains an unspecified vulnerability where the call initiator can cause the recipient's Apple device to answer unknowingly or without user interaction."
"CVE 2026"
"CVEs and Security Vulnerabilities - OpenCVE"
"CVE-2026-62223 | Tenable®"
"Vulnerability Database | SentinelOne"
"PSIRT | FortiGuard Labs"
"Apple says former employee exploited 'rare' bug to download confidential files after leaving for OpenAI"