vendor:
FaceTime
by:
Exploit Database
7.8
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: FaceTime
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: iOS
2020
Memory Corruption Issue in FaceTime
There is a memory corruption issue when processing a malformed RTP video stream in FaceTime that leads to a kernel panic due to a corrupted heap cookie or data abort. This bug can be reached if a user accepts a call from a malicious caller. This issue only affects FaceTime on iOS, it does not crash on a Mac. The issue can be reproduced using the attached sequence of RTP packets.
Mitigation:
Users should avoid accepting calls from unknown or suspicious callers.