CVE-2025-24271

MEDIUM

iPadOS < 17.7.6 - Unauthenticated AirPlay Command Execution via Network Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-24271. PoCs published by moften.

AI-analyzed exploit summary This PoC exploits CVE-2025-24271 by sending a fake AirPlay request to vulnerable Apple devices, potentially exposing sensitive information. It uses mDNS (Bonjour) to discover AirPlay devices and sends a crafted HTTP request to trigger the vulnerability.

Description

An access issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.

Exploits (1)

nomisec WORKING POC 4 stars
by moften · poc
https://github.com/moften/CVE-2025-24271

This PoC exploits CVE-2025-24271 by sending a fake AirPlay request to vulnerable Apple devices, potentially exposing sensitive information. It uses mDNS (Bonjour) to discover AirPlay devices and sends a crafted HTTP request to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Apple AirPlay (macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, iOS 18.4, iPadOS 17.7.6 and 18.4, tvOS 18.4, visionOS 2.4)
No auth needed
Prerequisites: Network access to vulnerable AirPlay devices · Python with zeroconf library installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122371
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122372
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122373
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122374
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122375
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122377
Release Notes, Vendor Advisory
https://support.apple.com/en-us/122378

Scores

CVSS v3 5.4
EPSS 0.0041
EPSS Percentile 32.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306 CWE-843
Status published
Products (12)
Apple/iOS and iPadOS < 18.4
apple/ipados < 17.7.6
Apple/iPadOS < 17.7.6
apple/iphone_os < 18.4
apple/macos < 13.7.5
Apple/macOS < 13.7.5
Apple/macOS < 14.7.5
Apple/macOS < 15.4
apple/tvos < 18.4
Apple/tvOS < 18.4
... and 2 more
Published Apr 29, 2025
Tracked Since Feb 18, 2026