CVE-2019-6224: Apple iPhone OS

High severity, CVSS 8.8. EPSS: 9% chance of exploitation in the next 30 days.

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A remote attacker may be able to initiate a FaceTime call causing arbitrary code execution.

Affected products

  • Apple iPhone OS: before 12.1.3 (fixed in 12.1.3)
  • Apple Mac OS X: before 10.14.3 (fixed in 10.14.3)
  • Apple Tv OS: before 12.1.2 (fixed in 12.1.2)
  • Apple watchOS: before 5.1.3 (fixed in 5.1.3)

Published 2019-03-05. Last modified 2026-06-17.