CVE-2025-24132
The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1 and AirPlay video SDK 3.6.0.126. An attacker on the local network may cause an unexpected app termination.
- Affected products
- Airplay Audio Sdk, Airplay Video Sdk, Carplay Communication Plug-In
- Apple Airplay Audio Software Development Kit
- < 2.7.1
- Apple Airplay Video Software Development Kit
- < 3.6.0.126
- Apple Carplay Communication Plug-in
- < r18.1
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 3.2% (87th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2025-04-30
CVE-2025-24132 at NVD
7 known exploits for CVE-2025-24132
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2025-24132-Scanner
LiberationPlay-CVE-2025-24132-AirBourne-POC
AirBorne-PoC
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Airplay_Audio_Software_Development_Kit
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Airplay_Audio_Software_Development_Kit
Exploit for Improper Restriction of Operations within the Bounds of a Memory Buffer in Apple Airplay_Audio_Software_Development_Kit
Exploit for Use After Free in Apple Ipados