CVE-2025-24271
MEDIUM 5.4EPSS 0.5%
An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.
- CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N - EPSS
- 0.49% chance of exploitation in the next 30 days, 40th percentile
- Published
- 2025-04-29
- Updated
- 2026-07-25
Proof-of-concept exploits (1)
- moften/CVE-2025-242714★ · 2025-04-30