- Security researchers found dozens of defects in Apple’s AirPlay protocol
- Some of them allowed execution attacks with remote code
- Apple has released patches that address the deficiencies
Apple’s AirPlay Protocol and AirPlay Software Development Kit (SDK) wore several vulnerabilities that could be abused to run Remote Code Execution (RCE) attack, male-in-the-mid (MITM) attack or denial of service (DOS) attacks. To make things worse, some of these vulnerabilities could be used in zero -click -click, which means pulling it off -no interaction from the victim is required.
CyberSecurity scientists oligo security found 23 shortcomings and called them collectively. Two of the deficiencies could be used in RCE attacks, which are now traced as CVE-2025-24252 and CVE-2025-24132. There is also CVE-2025-24206, a user interaction ulcer that allows Crooks to bypass “Accept” click requirements on AirPlay requests.
“This means that an attacker can take over certain appliances-activated devices and do things like implementing malware spreading to devices on any local network that the infected devices connect to. This can lead to the delivery of other sophisticated attacks related to espionage, ransomware, supply chain attacks and more,” warned oligo.
‘Big and approximately’
“Because AirPlay is a basic piece of software for Apple devices (Mac, iPhone, iPad, AppletV, etc.) as well as third-party devices utilizing AirPlay SDK, this class of vulnerabilities could have far-reaching effects.”
The potential range of airborne utilization is “huge and approximately”, Cyberinsides argues. The publication claims that Apple’s wireless streaming protocol is “critical” for the company’s ecosystem and operates at 2.35 billion active devices around the world.
It claims that a threat actor in theory could compromise a MacBook at a coffee shop and later use it as a springboard in a company network when the compromised unit connects to the company’s Wi-Fi.
Apple has since established the shortcomings of iOS and iPados 18.4, MacOS Ventura 13.7.5, MacOS Sonoma 14.7.5, MacOS Sequoia 15.4 and Visionos 2.4. AirPlay Audio SDK, AirPlay Video SDK and CarPlay Communication-plug-in have also been updated.
Via Bleeping computer