VDB

CVE-2019-25071

CVE-2019-25071 PUBLISHED CVSS 6.300000190734863 MEDIUM

A vulnerability was found in Apple iPhone up to 12.4.1. It has been declared as critical. Affected by this vulnerability is Siri. Playing an audio or video file might be able to initiate Siri on the same device which makes it possible to execute commands remotely. Exploit details have been disclosed to the public. The existence and implications of this vulnerability are doubted by Apple even though multiple public videos demonstrating the attack exist. Upgrading to version 13.0 migt be able to address this issue. It is recommended to upgrade affected devices. NOTE: Apple claims, that after examining the report they do not see any actual security implications.

EPSS 1.19% · 65.0th percentile

Risk Scores

CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
EPSS Score
1.19%
65.0th percentile

Affected Products

VendorProductVersions
AppleiOS12.4.0, 12.4.1
appleiphone_os0

Timeline

  • Jun 25, 2022 EPSS Score
  • Jun 25, 2022 CVE Published
  • Aug 13, 2022 EPSS Score
  • Sep 30, 2022 EPSS Score
  • Nov 16, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Feb 20, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 9, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 13, 2023 EPSS Score
  • Aug 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›