U.S. Committee Sends Letter to Tim Cook Asking for Answers About Group FaceTime Eavesdropping Flaw

The U.S. Committee on Energy & Commerce is now seeking answers from Apple over the Group FaceTime flaw that allowed people to eavesdrop on conversations.

Energy and Commerce Chairman Frank Pallone Jr. (D-NJ) and Consumer Protection and Commerce Subcommittee Chairwoman Jan Schakowsky (D-IL) today sent a letter [PDF] to Apple CEO Tim Cook questioning the company about how long it took Apple to address the Group ‌FaceTime‌ flaw, the extent to which the flaw compromised consumer privacy, and whether there are other undisclosed bugs in existence.

facetime bug duo

"While these are wonderful tools when used right, the serious privacy issue with Group FaceTime demonstrates how these devices can also become the ultimate spying machines. That is why it is critical that companies like Apple are held to the highest standards," Pallone and Schakowsky wrote to Cook. "Your company and others must proactively ensure devices and applications protect consumer privacy, immediately act when a vulnerability is identified, and address any harm caused when you fail to meet your obligations to consumers."

The two representatives ask Apple to be transparent about the investigation into the Group ‌FaceTime‌ vulnerability, and the steps that are being taken to protect consumer privacy going forward. Apple has not been as transparent as "this serious issue requires," according to the letter.

Pallone and Schakowsky ask Apple a number of key questions, including the following:

  • When did your company first identify the Group ‌FaceTime‌ vulnerability that enabled individuals to access the camera and microphone of devices before accepting a ‌FaceTime‌ call? Did your company identify the vulnerability before being notified by Mr. Thompson's mother?
  • Did any other customer notify Apple of the vulnerability?
  • Please provide a timeline of exactly what steps were taken and when they were taken to address the vulnerability after it was initially identified.
  • What steps are being taken to identify which ‌FaceTime‌ users' privacy interests were violated using the vulnerability? Does Apple intend to notify and compensate those consumers for the violation?
  • When will Apple provide notification to affected consumers?
  • Are there other vulnerabilities in Apple devices and applications that currently or potentially could result in unauthorized access to microphones and/or cameras?

Apple CEO ‌Tim Cook‌ will be expected to provide answers to the questions provided in the letter.

The FaceTime vulnerability came to light last Monday after details spread across social media and news sites quickly picked it up. The bug allowed a person to force a ‌FaceTime‌ call with another person, giving them access to the audio (and sometimes video) from an iPhone, iPad, or Mac without the person ever accepting the ‌FaceTime‌ call.

Apple disabled Group ‌FaceTime‌ on its servers to prevent the bug from being used, and the company is still working on an iOS 12.1.4 update that we are expecting to see this week.


While Apple addressed the bug after it went viral on social media, the company was informed of the issue at least a week before when a teenager discovered it and his mother attempted to contact Apple. Though she sent in multiple reports, they did not go to the right people, and Apple has since apologized and said it is committed to improving the bug reporting process.

Apple is already facing a lawsuit over the Group ‌FaceTime‌ issue and New York officials are also investigating.

Top Rated Comments

mozumder Avatar
68 months ago
Probably not a good idea to have a congressional hearing about every software bug..

Let Apple's track record about privacy speak for itself.
Score: 27 Votes (Like | Disagree)
PS8409 Avatar
68 months ago
Seems a bit over dramatized.
Score: 19 Votes (Like | Disagree)
thadoggfather Avatar
68 months ago
What a waste of time the letter is. Apple addressed it and the fix is being released soon.
They took over a week to respond to the formal complaint. That is not an acceptable grace period for 'privacy being top priority' in my view:

https://www.nytimes.com/2019/01/29/technology/facetime-glitch-apple.html

I think Apple is throwing stones from a glass house, and this won't be the last hiccup of theirs related to privacy
Score: 15 Votes (Like | Disagree)
AngerDanger Avatar
68 months ago
Whoa, little fella, what are you doing outside of the PRSI?
Score: 12 Votes (Like | Disagree)
trip1ex Avatar
68 months ago
What a waste of time the letter is. Apple addressed it and the fix is being released soon.
Score: 11 Votes (Like | Disagree)
dumastudetto Avatar
68 months ago
Why would anyone in authority concern themselves with customer privacy when they want backdoors inserted so they can spy on everyone with ease?
A more honest question would be why can't you create these flaws for us to exploit Mr. Cook?
Score: 10 Votes (Like | Disagree)

Popular Stories

Delta Feature

Delta Game Emulator Now Available From App Store on iPhone

Wednesday April 17, 2024 9:58 am PDT by
Game emulator apps have come and gone since Apple announced App Store support for them on April 5, but now popular game emulator Delta from developer Riley Testut is available for download. Testut is known as the developer behind GBA4iOS, an open-source emulator that was available for a brief time more than a decade ago. GBA4iOS led to Delta, an emulator that has been available outside of...
iOS NES Emulator Bimmy Feature

NES Emulator for iPhone and iPad Now Available on App Store [Removed]

Tuesday April 16, 2024 11:33 am PDT by
The first approved Nintendo Entertainment System (NES) emulator for the iPhone and iPad was made available on the App Store today following Apple's rule change. The emulator is called Bimmy, and it was developed by Tom Salvo. On the App Store, Bimmy is described as a tool for testing and playing public domain/"homebrew" games created for the NES, but the app allows you to load ROMs for any...
iPhone 15 Pro Action Button Translate

All iPhone 16 Models to Feature Action Button, But Usefulness Debated

Tuesday April 16, 2024 6:54 am PDT by
Last September, Apple's iPhone 15 Pro models debuted with a new customizable Action button, offering faster access to a handful of functions, as well as the ability to assign Shortcuts. Apple is poised to include the feature on all upcoming iPhone 16 models, so we asked iPhone 15 Pro users what their experience has been with the additional button so far. The Action button replaces the switch ...
maxresdefault

Hands-On With the New App Store Delta Game Emulator

Wednesday April 17, 2024 12:19 pm PDT by
A decade ago, developer Riley Testut released the GBA4iOS emulator for iOS, and since it was against the rules at the time, Apple put a stop to downloads. Emulators have been a violation of the App Store rules for years, but that changed on April 5 when Apple suddenly reversed course and said that it was allowing retro game emulators on the App Store. Subscribe to the MacRumors YouTube channel ...
iOS 18 Siri Integrated Feature

iOS 18 Will Add These New Features to Your iPhone

Friday April 12, 2024 11:11 am PDT by
iOS 18 is expected to be the "biggest" update in the iPhone's history. Below, we recap rumored features and changes for the iPhone. iOS 18 is rumored to include new generative AI features for Siri and many apps, and Apple plans to add RCS support to the Messages app for an improved texting experience between iPhones and Android devices. The update is also expected to introduce a more...