CVE-2025-66555
HIGHAirKeyboard iOS App 1.0.5 - Unauthenticated Remote Input Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-66555. PoCs published by Chokri Hammedi.
AI-analyzed exploit summary This exploit demonstrates a remote input injection vulnerability in the AirKeyboard iOS app by sending arbitrary keystrokes via an unauthenticated WebSocket connection on port 8888. The PoC constructs a JSON payload and sends it to the target device, allowing an attacker to inject text without user interaction.
Description
AirKeyboard iOS App 1.0.5 contains a missing authentication vulnerability that allows unauthenticated attackers to type arbitrary keystrokes directly into the victim's iOS device in real-time without user interaction, resulting in full remote input control.
Exploits (1)
This exploit demonstrates a remote input injection vulnerability in the AirKeyboard iOS app by sending arbitrary keystrokes via an unauthenticated WebSocket connection on port 8888. The PoC constructs a JSON payload and sends it to the target device, allowing an attacker to inject text without user interaction.
References (4)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N