Impact
The vulnerability is a state‑management flaw in Apple's FaceTime service that prevents the microphone mute setting from taking effect. When a user mutes the microphone during a call, the audio stream may continue to be transmitted, allowing others to hear what should have been silenced. This flaw can lead to confidentiality loss of the conversation, allowing an eavesdropper to capture private audio.
Affected Systems
Apple iOS and iPadOS devices running versions earlier than iOS 18.5 or iPadOS 18.5 are affected. The flaw has been addressed in iOS 18.5 and iPadOS 18.5, so any device still on an earlier release is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, while the EPSS score of less than 1% suggests a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a local or remote participant in an active FaceTime call who can trigger the mute function or cause the state change, as the defect manifests during the session. No public exploit has been reported, but the flaw’s moderate severity warrants timely remediation.
OpenCVE Enrichment
EUVD