A set of security vulnerabilities in Apple's AirPlay protocol and AirPlay application development software (SDK) exposed unpatched third-party devices as well as Apple devices , allowing various attacks, including remote code execution (RCE)
See also: Zero-Click vulnerability in macOS Calendar allows malicious actions

According to cybersecurity firm Oligo Security, which identified and reported the vulnerabilities, these vulnerabilities can be exploited in zero-click or one-click RCE attacks, man -in-the-middle (MITM) attacks, denial-of-service (DoS) attacks, as well as to bypass access control lists (ACLs) and avoid user interaction, with the aim of obtaining sensitive information or reading any local file.
In total, Oligo disclosed 23 vulnerabilities to Apple, which released security updates for iPhone and iPad (iOS 18.4 and iPadOS 18.4), Mac (macOS Ventura 13.7.5, macOS Sonoma 14.7.5, and macOS Sequoia 15.4), and Apple Vision Pro devices (visionOS 2.4). The company also patched vulnerabilities in the AirPlay Audio SDK, AirPlay Video SDK, and CarPlay Communication Plugin.
Although the AirBorne group's vulnerabilities can only be exploited by attackers who are on the same network via a wireless or peer-to-peer connection, they allow for complete control of vulnerable devices and use that access as a launching point to attack other AirPlay-enabled devices on the same network.
Security researchers at Oligo said they were able to demonstrate how two of the vulnerabilities (CVE-2025-24252 and CVE-2025-24132) can be used to create self-replicating zero-click remote code execution (RCE) attacks.
See also: Nepalese hacker reveals Facebook's Zero-Click vulnerability
Additionally, the CVE-2025-24206 user interaction bypass vulnerability allows an attacker to bypass the requirement to click “Accept” on AirPlay requests and can be combined with other vulnerabilities to perform zero-click attacks.

The cybersecurity firm recommends that organizations immediately update all corporate Apple devices and AirPlay-enabled devices to the latest software version, while also suggesting that employees be asked to update their personal AirPlay devices.
Additional measures users can take to reduce the attack surface include updating all Apple devices to the latest version, disabling the AirPlay receiver when not in use, restricting AirPlay access to only trusted devices via firewall rules, and limiting AirPlay usage to the current user only.
Apple says there are over 2.35 billion active Apple devices worldwide (including iPhones, iPads, Macs, and more), while Oligo estimates there are also tens of millions of third-party audio devices, such as speakers and TVs with AirPlay support, not counting car infotainment systems with CarPlay
See also: Apple: Serious Zero-Click vulnerability in Shortcuts app
Zero-click attacks , i.e. attacks that require no user action, are particularly dangerous because they can be carried out silently, without the victim realizing it. The fact that such attacks are now possible through AirPlay, a widely used protocol on Apple and third-party devices, shows how important it is to promptly apply security updates and limit the attack surface even to seemingly “innocent” functions such as wireless audio and video transmission.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
