CVE-2025-24252

Published Apr 29, 2025

Last updated 24 days ago

CVSS high 8.8
Apple
AirPlay

Overview

Description
A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt process memory.
Source
product-security@apple.com
NVD status
Modified
Products
ipados, iphone_os, macos, tvos, visionos

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-416

Social media

Hype score
Not currently trending
  1. Top 5 Trending CVEs: 1 - CVE-2024-1086 2 - CVE-2022-40982 3 - CVE-2025-24252 4 - CVE-2025-55182 5 - CVE-2026-21533 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    9 Mar 2026

    215 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨AirBorne: Full PoC Framework for CVE-2025-24252 & CVE-2025-24132 AirBorne is a combined proof-of-concept (PoC) framework targeting two serious vulnerabilities in Apple's AirPlay service. GitHub: https://t.co/PwxJ3jo2d3 https://t.co/BHOPAu3WWF

    @DarkWebInformer

    18 Oct 2025

    4357 Impressions

    3 Retweets

    18 Likes

    10 Bookmarks

    1 Reply

    0 Quotes

  3. Top 5 Trending CVEs: 1 - CVE-2024-11477 2 - CVE-2025-52970 3 - CVE-2024-30088 4 - CVE-2025-24252 5 - CVE-2025-5958 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    7 Sept 2025

    250 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2025-24252

    @transilienceai

    11 May 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2025-24252

    @transilienceai

    10 May 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🔥 วันวุ่น ๆ ของวัยรุ่นไอที! งานก็ยุ่งแล้ว ข่าวไซเบอร์ก็ยังแรงต่อเนื่อง วันนี้ทาง STH ได้รวบรวมข่าวที่

    @siamthanathack

    8 May 2025

    133 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Actively exploited CVE : CVE-2025-24252

    @transilienceai

    6 May 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. Critical AirPlay vulnerabilities (CVE-2025-24252, CVE-2025-24132) allow zero-click RCE over local Wi-Fi, affecting Apple devices & third-party receivers. Wormable exploit could spread autonomously across networks. Actions: •Update to latest OS versions •Restrict AirPla

    @redfoxsec

    6 May 2025

    83 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Actively exploited CVE : CVE-2025-24252

    @transilienceai

    5 May 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. New Apple exploit dropped. CVE-2025-24252 + CVE-2025-24132 = silent RCE Check em out if you like this shit

    @_0xHuCk

    5 May 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Zero-click. Wormable. Network-spreading. New flaws in Apple’s AirPlay protocol (🔓 AirBorne) could let hackers hijack your device without a click—then ride your Wi-Fi into corporate networks. CVE-2025-24252 + CVE-2025-24132 = silent RCE across Macs, TVs, speakers. Ju

    @TheHackersNews

    5 May 2025

    23878 Impressions

    97 Retweets

    226 Likes

    52 Bookmarks

    3 Replies

    7 Quotes

  12. Actively exploited CVE : CVE-2025-24252

    @transilienceai

    5 May 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. CVE-2025-24252 (CVSS:9.8, CRITICAL) is Analyzed. A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18..https://t.co/v25M9I0t3j #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    4 May 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Major Apple AirPlay vulnerability discovered by Oolgo Security! Zero-click RCE (CVE-2025-24252) affects macOS & AirPlay SDK, allowing malware installation without user interaction. Wormable exploit can spread across networks. Patch now or disable AirPlay receiver (port TCP700

    @salt_creative_

    1 May 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. PoCs for CVE-2025-24252 and CVE-2025-24132 Discovered and detailed by Oligo Security Poc by me of one of the many paths we can take to rce. #hacker #cybersecurity #EthicalHacking https://t.co/mNk2urVdN3

    @anoncitylights

    30 Apr 2025

    38 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 📱AirPlay Zero-Click Flaws Expose Apple Devices 23 vulnerabilities, including critical RCE flaws (CVE-2025-24252, CVE-2025-24132), let attackers take control of Apple devices with no user interaction. Espionage, ransomware, and supply chain risk. https://t.co/RMhBfTwGYg #Appl

    @dCypherIO

    30 Apr 2025

    52 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 Critical #vulnerability (CVE-2025-24252) discovered in #Apple OS, including macOS, iOS, iPadOS, tvOS & visionOS. Remote attackers can exploit a memory flaw. Patches available — update now. 🔒 Details: https://t.co/dGXncs8k0x #Cybersecurity #macOS #CVE2025

    @threatsbank

    30 Apr 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. AppleのAirPlayにおける脆弱性群"AirBorne"はゼロクリックでの遠隔コード実行につながる。Oligo Security社報告。修正済み。23件の脆弱性をAppleに報告しており、CVE-2025-24252とCVE-2025-24132の組み合わせがゼロクリック。CV

    @__kokumoto

    29 Apr 2025

    611 Impressions

    2 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  19. AirPlay Zero-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi (CVE-2025-24252)

    @minacrissDev_

    29 Apr 2025

    892 Impressions

    2 Retweets

    11 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 CVE-2025-24252 ⚠️🔴 CRITICAL (9.8) 🏢 Apple - tvOS 🏗️ unspecified 🔗 https://t.co/8NqQwzDxEL 🔗 https://t.co/dVpLdbOot2 🔗 https://t.co/QQxJQbWlNg 🔗 https://t.co/P3AJUA4VYU 🔗 https://t.co/GbpMieKtOF #CyberCron #VulnAlert #InfoSec https://t.co/kHLYqIC

    @cybercronai

    29 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVE-2025-24252 A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS… https://t.co/rkTFgt3xkz

    @CVEnew

    29 Apr 2025

    470 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations