Apple Products AirPlay Authentication Bypass Vulnerability

Vulnerability

A vulnerability exists in the AirPlay feature of multiple Apple products, including macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4, iPadOS 18.4, and visionOS 2.4. This vulnerability allows an attacker on the local network to bypass authentication policies, potentially leading to unauthorized access or actions.

Impact

Exploitation of this vulnerability could allow an attacker on the local network to bypass authentication policies, potentially leading to unauthorized access or actions on the affected device.

Reproduction

To reproduce this vulnerability, an attacker must be on the same local network as a signed-in Mac. The attacker can then send AirPlay commands to the Mac without pairing, bypassing the usual authentication process.

Remediation

Users can update to the latest versions of macOS Sequoia, tvOS, macOS Ventura, iPadOS, macOS Sonoma, iOS, and visionOS to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
5.0
remediation
7.7
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.