Apple AirPlay Authentication Bypass Vulnerability on macOS and tvOS

Vulnerability

A vulnerability exists in the AirPlay feature of multiple Apple operating systems, including macOS Sequoia 15.4, macOS Ventura 13.7.5, macOS Sonoma 14.7.5, tvOS 18.4, and visionOS 2.4. The issue allows an unauthenticated user on the same network as a signed-in Mac to send AirPlay commands without the need for pairing. This vulnerability could be exploited by an attacker on the local network to bypass authentication policies, potentially leading to unauthorized access or control over AirPlay-enabled devices.

Impact

Exploitation of this vulnerability could result in unauthorized AirPlay command execution on the affected device, allowing for potential manipulation of media playback or other AirPlay functions.

Remediation

Users can update to the latest versions of macOS Sequoia, macOS Ventura, macOS Sonoma, tvOS 18.4, or visionOS 2.4 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.7
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.