CVE-2025-31271
7.5Apple · macOS
A state management flaw in macOS allows incoming FaceTime calls to be visible or accepted on a locked device despite lock screen notification restrictions.
Executive summary
A security vulnerability in Apple macOS allows unauthorized interaction with FaceTime calls on locked devices, posing a risk to user privacy and device integrity.
Vulnerability
The vulnerability stems from improper state management within the FaceTime application. An unauthenticated attacker can trigger or accept incoming FaceTime calls on a locked device, bypassing configured lock screen notification settings.
Business impact
The ability to interact with FaceTime calls on a locked device facilitates unauthorized access to communication features and potential exposure of user information. Given the CVSS score of 7.5, this high-severity flaw represents a significant risk to device security and user privacy, as it permits interaction with the system without requiring user authentication.
Remediation
Immediate Action: Update all affected macOS systems to macOS Tahoe 26 or later to address the state management vulnerability.
Proactive Monitoring: Review system logs for unusual FaceTime activity or unauthorized interface interactions occurring while devices are in a locked state.
Compensating Controls: If immediate patching is not feasible, restrict FaceTime access or disable the application entirely on corporate-managed devices to prevent exploitation of this state management flaw.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a clear risk to the security posture of macOS deployments by circumventing standard lock screen access controls. Organizations should prioritize the deployment of macOS Tahoe 26 across all managed endpoints to ensure the vulnerability is fully remediated and to protect user communications from unauthorized access.