PoC Index

CVE-2025-24271

MEDIUM 5.4EPSS 0.5%

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
0.49% chance of exploitation in the next 30 days, 40th percentile
Published
2025-04-29
Updated
2026-07-25

Proof-of-concept exploits (1)

References

Related