Apple has disabled the Group FaceTime feature on the server side and reports suggest this has fixed the security flaw for most people
Software update still due later this week — Apple has temporarily disabled its Group FaceTime feature in iOS and macOS to fix a major security flaw.
Context & Ripple Effects
Group FaceTime arrived late to begin with: Apple pulled it from iOS 12's initial release last August and only shipped it that fall, per the developer beta release notes. On January 29, a flaw surfaced letting callers hear audio or view video before the recipient accepted or rejected the call as 9to5Mac reported.
Apple's response within the day was a server-side kill switch rather than waiting on a client update — and reports suggest that remote disablement alone closed the hole for most users. Days later it issued an apology and promised better bug reporting practices, with the full fix landing in iOS 12.1.4, whose accompanying FaceTime security audit also caught a Live Photos bug.
First-order effects
- Every iOS and macOS user of Group FaceTime lost the feature overnight, without installing anything — Apple flipped it off centrally while the client-side fix was still days away.
- Users exposed by the eavesdropping flaw were protected for most devices immediately, because the disablement acted at the server regardless of what version their phone ran.
Second-order effects
- The episode forced Apple into an unusual public apology and a commitment to improve how it receives bug reports, after the flaw circulated widely before any patch existed.
- Shipping the fix required more than one patch: Apple's post-incident security audit of FaceTime surfaced an additional Live Photos vulnerability, expanding the scope of the eventual iOS 12.1.4 release.
Third-order effects
- A server-side toggle proved fast enough to contain a client-side privacy hole, pointing toward platform vendors treating centralized feature switches as a first-line incident response tool ahead of scheduled updates.
- For consumer platforms generally, the pattern raises the bar on disclosure-to-mitigation speed — features that fail a privacy bar now risk being remotely retired until audited, as Group FaceTime effectively was between January 29 and February 8.
The trend: Consumer platform security is shifting toward server-side containment as the first response to client vulnerabilities, with OS updates relegated to the permanent fix.