Categories: Tech & Ai

Cybersecurity firm finds Apple AirPlay flaw, urges updates [May 2025]


This week, cybersecurity researchers with Oligo say they identified 23 vulnerabilities related to Apple AirPlay, leading Apple to issue over a dozen fixes.

Dubbed “AirBorne” by the researchers, the security vulnerabilities affect the Apple AirPlay network and could compromise various devices. According to an Oligo blog post, the researchers say the vulnerabilities “enable an array of attack vectors” that could allow “attackers to potentially take control of devices that support AirPlay — including both Apple devices and third-party devices that leverage the AirPlay [Software Development Kit].”

The Oligo blog outlines a number of potential attacks, including Zero-Click RCE, Man-in-the-Middle, and Denial of Service (DOS) attacks. But if you don’t know what any of that means, that’s OK — the solution for Apple users is fairly straightforward.

Essentially, as long as you update your devices to the latest versions of macOS, iOS, and iPadOS, your devices should be safe. In addition, some cybersecurity experts recommend disabling the AirPlay feature entirely unless you’re actively using it.

Mashable Light Speed

The “AirBorne” vulnerabilities would allow hackers to infect Apple devices with malware or seize control of the device, whether that’s a MacBook or iPhone. They could then deploy malware or steal sensitive information. AirBorne also affected third-party devices connected to AirPlay, leaving smart Internet-of-things (IOT) devices at risk.

The researchers say they worked with Apple to “identify and address” the flaws, and that Apple issued 17 CVEs in response to the research.

In the cybersecurity world, CVE stands for Common Vulnerabilities and Exposures, and it refers to a specific identifying number associated with a publicly disclosed cybersecurity problem. In a national CVE database hosted by the National Institute of Standards and Technology, users can find a number of new CVEs published by Apple on April 28, 2025, such as CVE-2025-24252 and CVE-2025-24206.

The CVE description states that Apple fixed these bugs in “in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4.”





Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Meme Coins on the Rebound as Bitcoin (BTC) Consolidation Continues (Weekend Watch)

Bitcoin’s relatively dull price movements as of late continued in the past 24 hours, but…

16 minutes ago

Y Combinator startup Firecrawl is ready to pay $1M to hire three AI agents as employees

Y Combinator-backed startup Firecrawl is back on the hunt for AI agent employees. As we…

23 minutes ago

Tether tightens grip as stablecoin market cap hits $243b

Stablecoins, like Tether USD Coin, continued their strong growth this week, with their market capitalization…

1 hour ago

Chelsea vs. Manchester United 2025 livestream: Watch Women’s FA Cup final for free

TL;DR: Live stream Chelsea vs. Manchester United in the Women's FA Cup final for free…

1 hour ago

Report: VCs See Stablecoins as Crypto’s ‘Killer App’

Despite the geopolitical tensions from the U.S. trade war causing a decline in most liquid…

1 hour ago

Can Ripple (XRP) Hit $10 in 2025? ChatGPT Answers

TL;DR The cryptocurrency space is full of bullish and sometimes relatively ridiculous price predictions for…

2 hours ago