CVE-2025-24132

MEDIUM

Apple Airplay Audio Software Development Kit - Memory Corruption

Title source: rule

Description

The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.

Exploits (6)

github WORKING POC 152 stars
by ekomsSavior · pythonpoc
https://github.com/ekomsSavior/AirBorne-PoC
github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-24132
nomisec WORKING POC 3 stars
by Feralthedogg · poc
https://github.com/Feralthedogg/CVE-2025-24132-Scanner
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-24132
nomisec WORKING POC 1 stars
by TheGamingGallifreyan · poc
https://github.com/TheGamingGallifreyan/LiberationPlay-CVE-2025-24132-AirBourne-POC
nomisec WORKING POC
by TheGamingGallifreyan · poc
https://github.com/TheGamingGallifreyan/LiberationPlay-CVE-2025-24132-AirBourne-Crash-POC

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (5)
Apple/AirPlay audio SDK < 2.7.1
apple/airplay_audio_software_development_kit < 2.7.1
Apple/AirPlay video SDK < 2.7.1
apple/airplay_video_software_development_kit < 3.6.0.126
apple/carplay_communication_plug-in < r18.1
Published Apr 30, 2025
Tracked Since Feb 18, 2026