Vulnerability Watch

Forum Discussion

Anonymous's avatar
Anonymous
6 years ago

Apple devices that support FaceTime Group Calling are...

Apple devices that support FaceTime Group Calling are vulnerable to a bug that could allow anyone to eavesdrop on audio conversations and access front facing video without the recipient answering the call.

Apple has since disabled group facetime calling[2], and Tenable will have mobile plugins available shortly after Apple releases a software update to fix this issue.

[1]https://www.buzzfeednews.com/article/nicolenguyen/facetime-bug-iphone

[2]https://www.nytimes.com/2019/01/28/technology/personaltech/facetime-bug-iphone-hack.html

3 Replies

  • Anonymous's avatar
    Anonymous

    Apple has released security updates for iOS (version 12.1.4) and macOS (version 10.14.3) to address the FaceTime vulnerability as well as a few other bugs. The FaceTime vulnerability has been given a CVE identifier of CVE-2019-6223 and credited to Grant Thompson, the teen that discovered the vulnerability.

  • Anonymous's avatar
    Anonymous

    Original release date: March 12, 2019

    Microsoft has released updates to address multiple vulnerabilities in Microsoft software. A remote attacker could exploit some of these vulnerabilities to take control of an affected system.

    The Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review Microsoft’s March 2019 Security Update Summary and Deployment Information and apply the necessary updates.