Apple Releases iOS Update to Fix FaceTime Eavesdropping Flaw
Apple issues a comprehensive iOS update that fully resolves the Group FaceTime vulnerability which allowed attackers to secretly listen to and view users. The patch also addresses additional security flaws actively exploited in the wild.
Apple releases an iOS update that fully patches the Group FaceTime vulnerability, a logic flaw tracked as CVE-2019-6223 that allows attackers to spy on users through their device's microphone and camera. The bug enables a malicious caller to add their own number to a group call and intercept audio and video before the victim actually answers. Apple addresses this issue through improved state management and completely restores the Group FaceTime service.
The tech giant credits 14-year-old Grant Thompson and Daven Morris for discovering and reporting the vulnerability. Apple admits it fails to properly handle the initial reports from Thompson and his mother, prompting a public apology and a promise to improve the vulnerability reporting process. The company pledges to award a bug bounty to Thompson, though it remains unclear if Morris receives similar compensation.
Beyond fixing the eavesdropping flaw, the iOS 12.1.4 update resolves two privilege escalation and code execution vulnerabilities that Google reports are actively exploited in the wild. Apple also patches a separate Live Photos issue in FaceTime tracked as CVE-2019-7288 via server-side validation. Despite these technical fixes, Apple faces legal trouble as a Texas lawyer files a lawsuit alleging the FaceTime bug is exploited to record a private deposition.