Skip to content

The FaceTime Bug That Let You Hear Before They Answered

Group FaceTime could transmit audio before a call was accepted. The repair addressed state management; the incident also exposed a reporting failure.

Episode 113 minute read

The boundary between ringing and connected

The security requirement is simple: an incoming call must not authorize audio transmission on behalf of the person receiving it. A feature can appear to work in its normal path while another sequence of state transitions violates that requirement.

Apple's advisory establishes the logic and state-management problem. It does not publish a complete reconstruction of its internal implementation or testing. The engineering lesson is to test consent as an invariant across call states, participant changes and interrupted transitions, rather than assuming a working group call demonstrates that all paths are safe.

A report that struggled to reach the right team

Grant Thompson, a teenager in Arizona, discovered the problem while calling friends. His family tried to alert Apple before the issue became widely public. The Associated Press reported their unsuccessful attempts over more than a week, and Apple's promise to improve its procedures.

Apple credited Thompson in its security update. It also announced a reward and a contribution toward his education. Those steps and the software repair matter, but they address different parts of the incident: the code needed a fix, and the reporting process needed to get a credible warning to people who could investigate it.

Intake is part of security

A vulnerability reporting channel should work for someone who has clear evidence but no specialist account or established relationship with the company. Reports need acknowledgment, triage and a path to escalation. Organizations can test that path just as they test a technical control.

For product teams, pair tests of expected behavior with tests of forbidden behavior. For security teams, measure the time from an outsider's first report to qualified review. A report that cannot reach an owner does not protect users simply because someone outside the company has already found the defect.

Sources

3 sources

Every figure in this article traces to one of the following: the same record the episode cites.

  1. Apple releases update to prevent FaceTime eavesdropping

    Associated Press (via Phys.org)2019

01Zof Console

姿勢、操作、次に注意が必要なことを 1 つの面で確認できます。

エンジニアリング、QA、SREの各チームが毎日開く認証済みのホーム。品質の姿勢、進行中の実行、モジュールごとのカバレッジ、そして次に注目すべきことが分かります。

運用上の KPI

実行数、カバレッジ、リスク

出荷先のあらゆる環境に対応します。

ワークスパイン

仕様・テスト・スケジュール

仕様から計画された回帰まで。

ガードレール

RBAC・SSO・監査

指定された人間に起因するすべての行為。

LIVE/console
Zof AI ホーム コマンド センターには、94% パスでの 12 件の実行、3 つの未解決の重大な問題、84% のカバレッジ、4 つのモジュール トレーサビリティ バー、仕様パイプライン、今後のスケジュール、アクティブ実行サイドバー付きの推奨される次のアクションが表示されます。
ホーム ビュー · チェックアウト サービス · ステージング · 製品からライブでキャプチャ。
The FaceTime Bug That Let You Hear Before They Answered | Zof AI