04.30.2025
Researchers at cybersecurity firm Oligo today outlined a series of AirPlay vulnerabilities that impact millions of Apple devices (via Wired) and accessories that connect to Apple devices. While Apple has

Dubbed "Airborne," the AirPlay vulnerabilities allowed attackers to take control of devices that support AirPlay to spread malware to other devices on any local device that the infected device connects to. An attacker would need to be on the same Wi-Fi network as the intended victim, putting public Wi-Fi spots, businesses, and other high-traffic areas at more risk.
Oligo researchers said that the AirPlay flaws could lead to "sophisticated attacks related to espionage, ransomware, supply-chain attacks, and more." The vulnerabilities could be used independently or chained together for a "variety of possible attack vectors," such as Remote Code Execution, user interaction bypass, Denial of Service attacks, Man-in-the-Middle attacks, and more.
Apple worked with Oligo to identify and fix the vulnerabilities. Oligo found 23 separate security flaws, and Apple issued 17 CVEs to address them. Information on each vulnerability is outlined on Oligo's website. Apple also deployed fixes for its AirPlay SDK for third-party manufacturers.
The same Airborne vulnerabilities also impact CarPlay, which could allow hackers to hijack the automotive computer in a car. This attack vector would require the attacker to be directly in the car and connected to either the car's Bluetooth or an in-car USB port, which makes it unlikely.
Oligo recommends that users upgrade to the latest versions of iOS, iPadOS, macOS, tvOS, and visionOS, to protect themselves from these vulnerabilities. Other devices that support AirPlay may still be vulnerable, so users should take steps like disabling the AirPlay Receiver feature on Macs and restricting AirPlay to the current user instead of all users.
Oligo CTO Gal Elbaz told Wired that there could be tens of millions of third-party AirPlay devices that are still vulnerable to attack. Because AirPlay is supported in such a wide variety of devices, there are a lot that will take years to patch--or they will never be patched," he said.
Tag: AirPlay
This article, "AirPlay Security Flaws Impact Third-Party Devices and Unpatched Apple Products" first appeared on MacRumors.com
Discuss this article in our forums
You may also be interested in this
CES 2024: Amazon Unveils …
01.09.2024
Amazon today announced Matter Casting, an interoperable rival to Apple's AirPlay feature, at CES 2024 (via Bloomberg). Matter Casting will initially only support streaming content from Amazon's Prime Video app
iOS 17’s New AirPla…
04.18.2024
Apple has announced that iPhone and iPad users can wirelessly stream videos, music, and photos from their device to their hotel room TV via AirPlay at select IHG Hotels &
Vision Pro and everything…
06.06.2023
Macworld Apple’s big keynote presentation to kick off WWDC 2023 was over two hours long. I’m as excited about new products as the next person, but who has that kind
Samsung’s new Smart Monit…
05.24.2023
Macworld Samsung on Tuesday revealed an update to its Smart Monitor M8, a stand-alone computer display. For customers looking for a high-resolution display but unable to afford Apple’s 5K Studio
9to5Mac Daily: June 23, 2…
06.23.2023
Listen to a recap of the top stories of the day from 9to5Mac. 9to5Mac Daily is available on iTunes and Apple’s Podcasts app, Stitcher, TuneIn, Google Play, or through our
iPhone media apps can pla…
06.20.2023
iOS 17 will make playing media from third-party sources easier on the HomePod by allowing you to AirPlay content from iPhone using Siri. (via Cult of Mac - Tech and
Streaming video via Apple…
04.18.2024
Find out how Apple just made it easier for iPhone and iPad users to stream content wirelessly to hotel room TVs with AirPlay. (via Cult of Mac - Apple news,
How to change the AirPlay…
06.08.2023
Macworld AirPlay lets you stream audio and video over a local network connection between an iPhone, iPad, or Mac to an Apple TV, HomePod, and lots of third-party devices with