Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-24271


An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An unauthenticated user on the same network as a signed-in Mac could send it AirPlay commands without pairing.


Published

2025-04-29T03:15:34.770

Last Modified

2025-04-30T16:15:34.560

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-306
    CWE-843

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System apple ipados < 17.7.6 Yes
Operating System apple ipados < 18.4 Yes
Operating System apple iphone_os < 18.4 Yes
Operating System apple macos < 13.7.5 Yes
Operating System apple macos < 14.7.5 Yes
Operating System apple macos < 15.4 Yes
Operating System apple tvos < 18.4 Yes
Operating System apple visionos < 2.4 Yes

References